Sploitus

CVE-2022-32532

2 known exploits for CVE-2022-32532

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

Affected products
Apache Shiro, Debian
Apache Shiro
< 1.9.1
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
27.2% (98th percentile)
Weakness
CWE-863
NVD status
Modified
Published
2022-06-28
CVE-2022-32532 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2022-32532

Proof-of-concept code and exploit modules indexed by Sploitus