You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Cause of vulnerability]
Shiro is used for authentication in hope-boot, but version 1.4.0 contains an insecure implementation
Meanwhile, hope-boot includes some interfaces configured without permission requirements, enabling the exploitation of vulnerabilities in Shiro's implementation to achieve authentication bypass.
The text was updated successfully, but these errors were encountered:
[Suggested description]
hope-boot was found to have an Incorrect Access Control vulnerability due to the use of an insecure version of Shiro.
[Vulnerability Type]
Incorrect access control
[Vendor of Product]
https://github.com/java-aodeng/hope-boot
[Affected Product Code Base]
all version (<= 1.0.0-release)
[Affected Component]
/user/edit/ interface
[Attack Type]
Remote
[Vulnerability details]
Send the payload below to the interface /user/edit/
The text was updated successfully, but these errors were encountered: