CVE-2022-32532: Authentication Bypass Vulnerability
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.
Other sources
Apache Shiro could allow a remote attacker to bypass security restrictions, caused by a flaw in the RegexRequestMatcher configuration. By using RegExPatternMatcher with "." in the regular expression, an attacker could exploit this vulnerability to bypass access restrictions.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-32532.
What is the title of this vulnerability?
The title of this vulnerability is 'Apache Shiro before 1.9.1 A RegexRequestMatcher can be misconfigured to be bypassed on some servlet …'
What is the description of this vulnerability?
The description of this vulnerability is that Apache Shiro before 1.9.1, a RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers, and applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
What is the severity of CVE-2022-32532?
The severity of CVE-2022-32532 is critical.
What is the affected software by CVE-2022-32532?
The affected software by CVE-2022-32532 is Apache Shiro before version 1.9.1.
How can I fix CVE-2022-32532?
To fix CVE-2022-32532, update Apache Shiro to version 1.9.1 or newer.