Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-32532

Опубликовано: 29 июн. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Высокий

Описание

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*
Версия до 1.9.1 (исключая)

EPSS

Процентиль: 99%
0.78671
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 8.1
redhat
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
debian
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured ...

CVSS3: 9.8
github
больше 3 лет назад

Improper Authorization in Apache Shiro

EPSS

Процентиль: 99%
0.78671
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-863
CWE-863