CVE-2014-0074

Source
https://nvd.nist.gov/vuln/detail/CVE-2014-0074
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-0074.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-0074
Downstream
Published
2014-10-06T14:55:08Z
Modified
2025-08-09T20:01:27Z
Summary
[none]
Details

Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.

References

Affected packages