
1. Apache Shiro Auth Bypass (CVE-2020-1957) I By simply injecting a /..;/ payload into the URL (Path Traversal), the obsolete Shiro framework got confused, granting me unauthorized access to protected internal APIs without any admin credentials.
Post summary
The post illustrates that Apache Shiro’s authentication bypass can be triggered via a simple \/..;/ payload, granting unauthorized API access without credentials.
