Authentication Bypass Vulnerability
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 25%
probabilidad de explotación
25%top 2% de las CVE
explotación observada
noninguna fuente lo reporta
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Productos afectados
Apache Software Foundation · Apache Shiro