Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cf5-xmhp-3xj7

Опубликовано: 30 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Improper Authorization in Apache Shiro

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

Пакеты

Наименование

org.apache.shiro:shiro-core

maven
Затронутые версииВерсия исправления

< 1.9.1

1.9.1

EPSS

Процентиль: 98%
0.27156
Средний

9.8 Critical

CVSS3

Дефекты

CWE-285
CWE-863

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 8.1
redhat
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
nvd
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
debian
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured ...

EPSS

Процентиль: 98%
0.27156
Средний

9.8 Critical

CVSS3

Дефекты

CWE-285
CWE-863