---
cve: "CVE-2020-1957"
severity: "LOW"
cvss: 3.1
epss: "23.3%"
vendor: "n/a"
kev: false
exploited: false
published: "2020-03-25 15:24:27"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T05:15:58+02:00"
---

# CVE-2020-1957

> 3.1 LOW

## Beschreibung

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

## Patch verfügbar (OSV)

- d1653b888509e1c2b280b5fd8f15dfcf8d8da56f (Commit)

## Referenzen

- <https://lists.apache.org/thread.html/r17f371fc89d34df2d0c8131473fbc68154290e1be238895648f5a1e6%40%3Cdev.shiro.apache.org%3E>
- <https://lists.apache.org/thread.html/rc64fb2336683feff3580c3c3a8b28e80525077621089641f2f386b63%40%3Ccommits.camel.apache.org%3E>
- <https://lists.apache.org/thread.html/rb3982edf8bc8fcaa7a308e25a12d294fb4aac1f1e9d4e14fda639e77%40%3Cdev.geode.apache.org%3E>
- <https://lists.debian.org/debian-lts-announce/2020/04/msg00014.html>
- <https://lists.apache.org/thread.html/rc8b39ea8b3ef71ddc1cd74ffc866546182683c8adecf19c263fe7ac0%40%3Ccommits.shiro.apache.org%3E>
- <https://lists.apache.org/thread.html/r2d2612c034ab21a3a19d2132d47d3e4aa70105008dd58af62b653040%40%3Ccommits.shiro.apache.org%3E>
- <https://lists.apache.org/thread.html/rab1972d6b177f7b5c3dde9cfb0a40f03bca75f0eaf1d8311e5762cb3%40%3Ccommits.shiro.apache.org%3E>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2020-1957) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
