Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-32532

Опубликовано: 29 июн. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*
Версия до 1.9.1 (исключая)

EPSS

Процентиль: 98%
0.27156
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 8.1
redhat
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
debian
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured ...

CVSS3: 9.8
github
около 4 лет назад

Improper Authorization in Apache Shiro

EPSS

Процентиль: 98%
0.27156
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-863
CWE-863