|
Message-ID: <CAH9eYVqfx9RvVpg34arMu4unNkmzwAbtL2umS+41atCZAVyctw@mail.gmail.com> Date: Tue, 28 Jun 2022 15:32:01 -0400 From: Brian Demers <bdemers@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2022-32532: Apache Shiro: Authentication Bypass Vulnerability Description: Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass. Credit: Apache Shiro would like the thank 4ra1n for reporting this issue.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.