PT-2023-8779 · Spring+2 · Spring Boot+2

CVE-2023-22602

·

Published

2023-01-13

·

Updated

2023-08-31

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Shiro versions prior to 1.11.0 Spring Boot versions 2.6+
Description The issue is related to a conflict of interpretations between Apache Shiro and Spring Boot, which can be exploited by a remote attacker using a specially crafted HTTP request to bypass authentication. This occurs when Shiro and Spring Boot use different pattern-matching techniques, with both defaulting to Ant style pattern matching in versions prior to Spring Boot 2.6.
Recommendations Update to Apache Shiro 1.11.0 Set the Spring Boot configuration value: spring.mvc.pathmatch.matching-strategy = ant path matcher

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01896
CVE-2023-22602
GHSA-7CXR-H8WM-FG4C

Affected Products

Apache Shiro
Debian
Spring Boot