Candidate: CVE-2016-4437 PublicDate: 2016-06-07 14:06:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4437 Description: Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_shiro: upstream_shiro: released (1.2.5-1) precise_shiro: DNE precise/esm_shiro: DNE trusty_shiro: DNE trusty/esm_shiro: DNE vivid/stable-phone-overlay_shiro: DNE vivid/ubuntu-core_shiro: DNE wily_shiro: ignored (reached end-of-life) xenial_shiro: ignored (end of standard support, was needed) yakkety_shiro: ignored (reached end-of-life) zesty_shiro: ignored (reached end-of-life) artful_shiro: ignored (reached end-of-life) bionic_shiro: not-affected (1.3.2-2) cosmic_shiro: not-affected (1.3.2-2) disco_shiro: not-affected (1.3.2-2) eoan_shiro: not-affected (1.3.2-2) focal_shiro: not-affected (1.3.2-2) groovy_shiro: not-affected (1.3.2-2) hirsute_shiro: not-affected (1.3.2-2) impish_shiro: not-affected (1.3.2-2) jammy_shiro: not-affected (1.3.2-2) devel_shiro: not-affected (1.3.2-2)