VDB
Sign up
MEDIUM5.3

GHSA-c244-p6m5-vqj6

Apache Shiro has an Authentication Bypass

Quick fix

GHSA-c244-p6m5-vqj6 — org.apache.shiro:shiro-spring: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.1.0</version> for org.apache.shiro:shiro-spring

Details

### Impact

**Authentication Bypass:** A vulnerability exists in Apache Shiro that allows authentication bypass for static files when served from a case-insensitive filesystem (such as the default configuration on macOS or Windows).

The issue arises when Shiro's URL filters are configured with lower-case rules (a common default), but the underlying operating system treats mixed-case filenames as identical. An attacker can access protected static resources by varying the capitalization of the filename in the request (e.g., requesting `/SECRET.TXT` to bypass a rule for `/secret.txt`).

This issue specifically affects static file handling and does not impact dynamic resource paths that are case-sensitive.

### Patches Users should upgrade to Apache Shiro **2.1.0** or later.

**Important Configuration Note:** Version 2.1.0 introduces a new configuration parameter to handle case-insensitivity, which must be enabled manually to resolve the issue:

* **shiro.ini:** ```ini filterChainResolver.caseInsensitive = true ``` * **Spring Boot (application.properties):** ```properties shiro.caseInsensitive=true ```

*Note: Apache Shiro 3.0.0 (upcoming) will enable this setting by default.*

### Workarounds * Ensure that the filesystem hosting the application is case-sensitive (e.g., Linux/Unix). * Manually configure all Shiro filter chains to handle all possible case variations of protected filenames (not recommended due to complexity).

### Resources * [CVE-2026-23903](https://nvd.nist.gov/vuln/detail/CVE-2026-23903) * [Mailing List Announcement](https://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k) * [OSS-Security List](http://www.openwall.com/lists/oss-security/2026/02/08/1)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.shiro:shiro-spring
Introduced in: 0Fixed in: 2.1.0
Fix# pom.xml: bump <version>2.1.0</version> for org.apache.shiro:shiro-spring

References