CVE-2016-4437
CISA 기관 조치 기한: 2022-05-03
Apache Shiro
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
KEV 필수 조치: Apply updates per vendor instructions.
공개 익스플로잇 / PoC
- Exploit-DB: EDB-48410 ↗