Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-32532

Опубликовано: 28 июн. 2022
Источник: redhat
CVSS3: 8.1
EPSS Средний

Описание

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

A flaw was sound in Apache Shiro's RegexRequestMatcher, which can be misconfigured and bypassed on some servlet containers. Applications using RegExPatternMatcher with '.' in the regular expression are vulnerable to an authorization bypass.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Quarkusshiro-coreAffected
Red Hat Fuse 7shiro-coreOut of support scope
Red Hat Integration Camel K 1shiro-coreAffected
Red Hat Integration Camel Quarkus 1shiro-coreAffected
Red Hat JBoss A-MQ 6shiro-coreOut of support scope
Red Hat JBoss Enterprise Application Platform 7shiro-coreNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packshiro-coreNot affected
Red Hat JBoss Fuse 6shiro-coreOut of support scope
Red Hat JBoss Fuse Service Works 6shiro-coreOut of support scope
Red Hat OpenShift Application Runtimesshiro-coreAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2107130shiro: authorization bypass due to possible misconfigured

EPSS

Процентиль: 98%
0.27156
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
nvd
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
debian
около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured ...

CVSS3: 9.8
github
около 4 лет назад

Improper Authorization in Apache Shiro

EPSS

Процентиль: 98%
0.27156
Средний

8.1 High

CVSS3