CVE-2022-32532: vulnerability in Apache Shiro
Authentication Bypass Vulnerability
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 26%
exploitation probability
26%top 2% of all CVEs
observed exploitation
nono source reports it
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Affected products
Apache Software Foundation · Apache ShiroRelated CVEs — Apache Shiro
In the same product, most dangerous first.
CVE-2021-41303—Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypassEPSS 76.7%CVE-2020-11989—CVE-2020-11989EPSS 24.4%CVE-2022-40664CRITICALAuthentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcherEPSS 2.7%CVE-2023-34478CRITICALApache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.EPSS 2.1%CVE-2023-22602—Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP requestEPSS 1.6%CVE-2023-46750MEDIUMApache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.EPSS 1.5%