Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-22602
HistoryJan 14, 2023 - 10:15 a.m.

Authentication flaw

2023-01-1410:15:00
PRIOn knowledge base
www.prio-n.com
6
apache shiro
spring boot
authentication bypass
http request
pattern matching
mitigation
update
nvd

7.7 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.1%

When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching. Mitigation: Update to Apache Shiro 1.11.0, or set the following Spring Boot configuration value: spring.mvc.pathmatch.matching-strategy = ant_path_matcher

CPENameOperatorVersion
shirolt1.11.0
spring_booteq2.6.0

7.7 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.1%