← back
CVE-2022-32532CWE-863

Authentication Bypass Vulnerability

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 25%
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.