CVE-2020-11989: shiro: spring dynamic controllers, a specially crafted request may cause an authentication bypass

Severity: Critical

CVSS Score: 9.8

Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.