When using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass. Upstream Advisory: https://lists.apache.org/thread.html/r17f371fc89d34df2d0c8131473fbc68154290e1be238895648f5a1e6%40%3Cdev.shiro.apache.org%3E
Created shiro tracking bugs for this issue: Affects: fedora-all [bug 1829282]
Statement: Whilst the OpenDaylight version that is included in Red Hat OpenStack Platform includes the affected code, the vulnerable function is not used and therefore not exploitable.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-1957