Lucene search

K
cvelistApacheCVELIST:CVE-2022-32532
HistoryJun 28, 2022 - 11:20 p.m.

CVE-2022-32532 Authentication Bypass Vulnerability

2022-06-2823:20:11
CWE-863
apache
www.cve.org

9.6 High

AI Score

Confidence

High

0.04 Low

EPSS

Percentile

92.1%

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.

CNA Affected

[
  {
    "product": "Apache Shiro",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "Before 1.9.1"
      }
    ]
  }
]

9.6 High

AI Score

Confidence

High

0.04 Low

EPSS

Percentile

92.1%