Sploitus

Exploit for shiro

kitploit Β· 2026-08-25

Exploit Code

MARKDOWN115 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-MY0113-SHIRO-CVE-2022-32532
# Apache Shiro CVE-2022-32532 Π‘Ρ€Π΅Π΄Π° воспроизвСдСния

Π­Ρ‚ΠΎ минимальноС Π²Π΅Π±-ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠ΅ для воспроизвСдСния **CVE-2022-32532** (ΠΎΠ±Ρ…ΠΎΠ΄ Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΠΈ Apache Shiro RegExPatternMatcher).

## ОписаниС уязвимости

  * **CVE** : CVE-2022-32532
  * **ВСрсии ΠΏΠΎΠ΄ ΡƒΠ³Ρ€ΠΎΠ·ΠΎΠΉ** : Shiro < 1.9.1
  * **ΠŸΡ€ΠΈΡ‡ΠΈΠ½Π°** : `RegExPatternMatcher` Π½Π΅ΠΏΡ€Π°Π²ΠΈΠ»ΡŒΠ½ΠΎ закрСпляСт рСгулярноС Π²Ρ‹Ρ€Π°ΠΆΠ΅Π½ΠΈΠ΅, Ρ‡Ρ‚ΠΎ ΠΌΠΎΠΆΠ΅Ρ‚ привСсти ΠΊ ΠΎΠ±Ρ…ΠΎΠ΄Ρƒ ΠΏΡƒΡ‚ΠΈ. Π’ частности, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΠ΅Ρ‚ΡΡ Π»ΠΎΠ³ΠΈΠΊΠ° сопоставлСния рСгСкспов ΠΏΠΎ ΡƒΠΌΠΎΠ»Ρ‡Π°Π½ΠΈΡŽ Π² Java, ΠΈ ΠΊΠΎΠ³Π΄Π° встрСчаСтся символ `.` ΠΊΠ°ΠΊ Ρ‡Π°ΡΡ‚ΡŒ рСгСкспа, ΠΈΠ³Π½ΠΎΡ€ΠΈΡ€ΡƒΡŽΡ‚ΡΡ ΡΠΏΠ΅Ρ†ΠΈΠ°Π»ΡŒΠ½Ρ‹Π΅ символы, Ρ‚Π°ΠΊΠΈΠ΅ ΠΊΠ°ΠΊ `\r` (%0d) ΠΈ `\n` (%0a). НСобходимо явно ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚ΡŒ Ρ€Π΅ΠΆΠΈΠΌ `Pattern.DOTALL` для ΠΊΠΎΡ€Ρ€Π΅ΠΊΡ‚Π½ΠΎΠΉ ΠΎΠ±Ρ€Π°Π±ΠΎΡ‚ΠΊΠΈ `\r` ΠΈ `\n`. ВСрсии Shiro Π½ΠΈΠΆΠ΅ 1.9.1 ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡŽΡ‚ Π»ΠΎΠ³ΠΈΠΊΡƒ сопоставлСния ΠΏΠΎ ΡƒΠΌΠΎΠ»Ρ‡Π°Π½ΠΈΡŽ, поэтому Π½Π΅ ΠΌΠΎΠ³ΡƒΡ‚ ΠΊΠΎΡ€Ρ€Π΅ΠΊΡ‚Π½ΠΎ ΠΎΠ±Ρ€Π°Π±Π°Ρ‚Ρ‹Π²Π°Ρ‚ΡŒ `\r` ΠΈ `\n`, Ρ‡Ρ‚ΠΎ ΠΏΡ€ΠΈΠ²ΠΎΠ΄ΠΈΡ‚ ΠΊ ΠΎΠ±Ρ…ΠΎΠ΄Ρƒ Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΠΈ.



## Как воспроизвСсти

  1. ЗапуститС ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠ΅

root@kitploit:~
         
         启动ShiroCve202232532Application
         
         

  2. URL-адрСс, ΠΊΠΎΡ‚ΠΎΡ€Ρ‹ΠΉ ΠΏΡ€ΠΈ Π½ΠΎΡ€ΠΌΠ°Π»ΡŒΠ½ΠΎΠΉ Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΠΈ Ρ‡Π΅Ρ€Π΅Π· Shiro Π²ΠΎΠ·Π²Ρ€Π°Ρ‰Π°Π΅Ρ‚ access denied:  
http://localhost:8080/permit/xxx, Π³Π΄Π΅ xxx ΠΌΠΎΠΆΠ΅Ρ‚ Π±Ρ‹Ρ‚ΡŒ Π»ΡŽΠ±Ρ‹ΠΌΠΈ символами

  3. URL-адрСс, ΠΊΠΎΡ‚ΠΎΡ€Ρ‹ΠΉ ΠΎΠ±Ρ…ΠΎΠ΄ΠΈΡ‚ Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΠΊΠ°Ρ†ΠΈΡŽ Shiro ΠΈ Π²ΠΎΠ·Π²Ρ€Π°Ρ‰Π°Π΅Ρ‚ success:  
http://localhost:8080/permit/xxx, Ρ‚ΠΎ Π΅ΡΡ‚ΡŒ Π²ΡΡ‚Π°Π²ΡŒΡ‚Π΅ Π² xxx символы пСрСноса строки \n (%0a) ΠΈ Π²ΠΎΠ·Π²Ρ€Π°Ρ‚Π° ΠΊΠ°Ρ€Π΅Ρ‚ΠΊΠΈ \r (%0d)

  4. ΠœΠ΅Ρ‚ΠΎΠ΄ исправлСния

     1. Π‘ΠΊΠΎΠΏΠΈΡ€ΡƒΠΉΡ‚Π΅ ΠΏΠΎΠ»Π½ΠΎΠ΅ содСрТимоС `RegExPatternMatcher.java` ΠΈ `PatternMatcher.java` ΠΈΠ· https://github.com/apache/shiro/blob/shiro-root-1.9.1/core/src/main/java/org/apache/shiro/util/.
     2. Π‘ΠΊΠΎΠΌΠΏΠΈΠ»ΠΈΡ€ΡƒΠΉΡ‚Π΅ эти Π΄Π²Π° .java Ρ„Π°ΠΉΠ»Π° Π² `RegExPatternMatcher.class` ΠΈ `PatternMatcher.class` с ΠΏΠΎΠΌΠΎΡ‰ΡŒΡŽ JDK 11.
     3. ΠŸΠΎΠΌΠ΅ΡΡ‚ΠΈΡ‚Π΅ эти 2 class-Ρ„Π°ΠΉΠ»Π° Π² `shiro-core-1.6.0.jar` ΠΏΠΎ ΠΏΡƒΡ‚ΠΈ `org/apache/shiro/util/` с ΠΏΠΎΠΌΠΎΡ‰ΡŒΡŽ WinRAR.
     4. Для тСстирования исправлСния скопируйтС ΠΊΠΎΠ΄ ΠΈΠ· `RegExPatternMatcher.java` ΠΈΠ· shiro-core-1.9.1 Π² Π΄Π°Π½Π½Ρ‹ΠΉ ΠΏΡ€ΠΈΠΌΠ΅Ρ€, ΠΏΠ΅Ρ€Π΅ΠΈΠΌΠ΅Π½ΠΎΠ²Π°Π² Π² , Π·Π°Ρ‚Π΅ΠΌ Π·Π°ΠΌΠ΅Π½ΠΈΡ‚Π΅  Π² строкС 15  ΠΈ строкС 29  Π½Π° .



root@kitploit:~
    
    
    /*
     * Licensed to the Apache Software Foundation (ASF) under one
     * or more contributor license agreements.  See the NOTICE file
     * distributed with this work for additional information
     * regarding copyright ownership.  The ASF licenses this file
     * to you under the Apache License, Version 2.0 (the
     * "License"); you may not use this file except in compliance
     * with the License.  You may obtain a copy of the License at
     *
     *     http://www.apache.org/licenses/LICENSE-2.0
     *
     * Unless required by applicable law or agreed to in writing,
     * software distributed under the License is distributed on an
     * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
     * KIND, either express or implied.  See the License for the
     * specific language governing permissions and limitations
     * under the License.
     */
    package org.apache.shiro.util;
    
    import java.util.regex.Pattern;
    import java.util.regex.Matcher;
    
    /**
     * {@code PatternMatcher} implementation that uses standard {@link java.util.regex} objects.
     *
     * @see Pattern
     * @since 1.0
     */
    public class RegExPatternMatcher implements PatternMatcher {
    
       private static final int DEFAULT = Pattern.DOTALL;
    
       private static final int CASE_INSENSITIVE = DEFAULT | Pattern.CASE_INSENSITIVE;
    
       private boolean caseInsensitive = false;
    
       /**
        * Simple implementation that merely uses the default pattern comparison logic provided by the
        * JDK.
        * <p/>This implementation essentially executes the following:
        * <pre>
        * Pattern p = Pattern.compile(pattern, Pattern.DOTALL);
        * Matcher m = p.matcher(source);
        * return m.matches();</pre>
        * @param pattern the pattern to match against
        * @param source  the source to match
        * @return {@code true} if the source matches the required pattern, {@code false} otherwise.
        */
       public boolean matches(String pattern, String source) {
          if (pattern == null) {
             throw new IllegalArgumentException("pattern argument cannot be null.");
          }
          Pattern p = Pattern.compile(pattern, caseInsensitive ? CASE_INSENSITIVE : DEFAULT);
          Matcher m = p.matcher(source);
          return m.matches();
       }
    
       /**
        * Returns true if regex match should be case-insensitive.
        * @return true if regex match should be case-insensitive.
        */
       public boolean isCaseInsensitive() {
          return caseInsensitive;
       }
    
       /**
        * Adds the Pattern.CASE_INSENSITIVE flag when compiling patterns.
        * @param caseInsensitive true if patterns should match case-insensitive.
        */
       public void setCaseInsensitive(boolean caseInsensitive) {
          this.caseInsensitive = caseInsensitive;
       }
    }