Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-32532

Опубликовано: 28 июн. 2022
Источник: redhat
CVSS3: 8.1
EPSS Высокий

Описание

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

A flaw was sound in Apache Shiro's RegexRequestMatcher, which can be misconfigured and bypassed on some servlet containers. Applications using RegExPatternMatcher with '.' in the regular expression are vulnerable to an authorization bypass.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Quarkusshiro-coreAffected
Red Hat Fuse 7shiro-coreOut of support scope
Red Hat Integration Camel K 1shiro-coreAffected
Red Hat Integration Camel Quarkus 1shiro-coreAffected
Red Hat JBoss A-MQ 6shiro-coreOut of support scope
Red Hat JBoss Enterprise Application Platform 7shiro-coreNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packshiro-coreNot affected
Red Hat JBoss Fuse 6shiro-coreOut of support scope
Red Hat JBoss Fuse Service Works 6shiro-coreOut of support scope
Red Hat OpenShift Application Runtimesshiro-coreAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2107130shiro: authorization bypass due to possible misconfigured

EPSS

Процентиль: 99%
0.78671
Высокий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
nvd
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 9.8
debian
больше 3 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured ...

CVSS3: 9.8
github
больше 3 лет назад

Improper Authorization in Apache Shiro

EPSS

Процентиль: 99%
0.78671
Высокий

8.1 High

CVSS3