Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-284",
"CWE-321"
],
"nvd_published_at": "2016-06-07T14:06:00Z",
"severity": "CRITICAL",
"github_reviewed_at": "2022-07-06T19:56:32Z"
}