Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cf5-xmhp-3xj7

Опубликовано: 30 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Improper Authorization in Apache Shiro

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

Пакеты

Наименование

org.apache.shiro:shiro-core

maven
Затронутые версииВерсия исправления

< 1.9.1

1.9.1

EPSS

Процентиль: 99%
0.78671
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-285
CWE-863

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 8.1
redhat
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
nvd
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
debian
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured ...

EPSS

Процентиль: 99%
0.78671
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-285
CWE-863