Skip to content

[GHSA-7pq2-fhx9-x464] Apache Shiro’s Jakarta EE module used the HTTP Referer...#7910

Open
yeikel wants to merge 1 commit into
yeikel/advisory-improvement-7910from
yeikel-GHSA-7pq2-fhx9-x464
Open

[GHSA-7pq2-fhx9-x464] Apache Shiro’s Jakarta EE module used the HTTP Referer...#7910
yeikel wants to merge 1 commit into
yeikel/advisory-improvement-7910from
yeikel-GHSA-7pq2-fhx9-x464

Conversation

@yeikel
Copy link
Copy Markdown

@yeikel yeikel commented Jun 8, 2026

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Summary

Comments
Documented package and affected version. Although CVE data suggests that a version with the fix exists, that is not the case yet

Comment on lines +21 to +27
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0.0-alpha-0"
}
Copy link
Copy Markdown
Author

@yeikel yeikel Jun 8, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hmm, I am not sure if the form actually captured what I tried to capture

Versions are

  • Apache Shiro (org.apache.shiro:shiro-jakarta-ee) 2.0.0-alpha-0 through 2.2.0
  • Apache Shiro (org.apache.shiro:shiro-jakarta-ee) 3.0.0-alpha-0 through 3.0.0-alpha-1

@github-actions github-actions Bot changed the base branch from main to yeikel/advisory-improvement-7910 June 8, 2026 03:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant