Red Hat Bugzilla – Bug 1375884
CVE-2016-6802 Apache Shiro: Security servlet filters bypass
Last modified: 2018-06-29 18:14:34 EDT
Apache Shiro before 1.3.2, when using a non-root servlet context path, specifically crafted requests can be used to by pass some security servlet filters, resulting in unauthorized access. References: http://seclists.org/oss-sec/2016/q3/488
Created shiro tracking bugs for this issue: Affects: fedora-24 [bug 1375885]
shiro-1.3.2-1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.