PT-2022-21353 · Apache+1 · Apache Shiro+1

4Ra1N

·

Published

2022-06-28

·

Updated

2022-07-08

·

CVE-2022-32532

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Shiro versions prior to 1.9.1
Description The issue concerns a potential misconfiguration of RegexRequestMatcher in certain servlet containers, which can lead to an authorization bypass. This affects applications that use RegExPatternMatcher with a regular expression containing the . character.
Recommendations For versions prior to 1.9.1, update to version 1.9.1 or later to resolve the issue. As a temporary workaround, consider reviewing and adjusting the configuration of RegexRequestMatcher to prevent potential bypasses, especially in applications using RegExPatternMatcher with . in the regular expression.

Exploit

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32532
GHSA-4CF5-XMHP-3XJ7

Affected Products

Apache Shiro
Debian