Candidate: CVE-2016-6802 PublicDate: 2016-09-20 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6802 http://openwall.com/lists/oss-security/2016/09/13/3 Description: Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_shiro: upstream_shiro: released (1.3.2) precise_shiro: DNE precise/esm_shiro: DNE trusty_shiro: DNE trusty/esm_shiro: DNE vivid/stable-phone-overlay_shiro: DNE vivid/ubuntu-core_shiro: DNE xenial_shiro: ignored (end of standard support, was needed) yakkety_shiro: ignored (reached end-of-life) zesty_shiro: ignored (reached end-of-life) artful_shiro: ignored (reached end-of-life) bionic_shiro: not-affected (1.3.2-2) cosmic_shiro: not-affected (1.3.2-2) disco_shiro: not-affected (1.3.2-2) eoan_shiro: not-affected (1.3.2-2) focal_shiro: not-affected (1.3.2-2) groovy_shiro: not-affected (1.3.2-2) hirsute_shiro: not-affected (1.3.2-2) impish_shiro: not-affected (1.3.2-2) jammy_shiro: not-affected (1.3.2-2) devel_shiro: not-affected (1.3.2-2)