Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
{
"versions": [
{
"introduced": "0.10.0"
},
{
"fixed": "0.18.1"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.2.5"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.0"
}
]
}