CVE-2022-32532
published 2022-06-29CVE-2022-32532: Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
25.43%
97.7th percentile
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.9.1 | 1.9.1 |
| apache_software_foundation | apache_shiro | — | — |
| debian | shiro | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Applications using RegExPatternMatcher with '.' in the regular expression are vulnerable to authorization bypass via RegexRequestMatcher misconfiguration ↗
- →The vulnerability class is authorization bypass via misconfigured RegexRequestMatcher on certain servlet containers — audit Shiro configurations for use of RegExPatternMatcher with unescaped '.' in regex patterns ↗
- ·Only Apache Shiro versions before 1.9.1 are vulnerable; upgrade to 1.9.1 or later to remediate ↗
- ·The bypass is servlet-container-dependent; not all containers are affected, making exploitability environment-specific ↗
- ·Red Hat JBoss Enterprise Application Platform 7 and EAP Expansion Pack are confirmed NOT affected; other Red Hat products (Quarkus, Camel K, Camel Quarkus, OpenShift App Runtimes, OpenStack Platform 13) are affected ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache Shiro) — CVE-2022-32532
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2022-32532 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache Shiro) — CVE-2022-32532
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache Shiro) vulnerability
CVE: CVE-2022-32532
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Red Hat
shiro: authorization bypass due to possible misconfigured
vendor_redhat·2022-06-28·CVSS 9.8
CVE-2022-32532 [CRITICAL] CWE-863 shiro: authorization bypass due to possible misconfigured
shiro: authorization bypass due to possible misconfigured
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
A flaw was sound in Apache Shiro's RegexRequestMatcher, which can be misconfigured and bypassed on some servlet containers. Applications using RegExPatternMatcher with '.' in the regular expression are vulnerable to an authorization bypass.
Package: shiro-core (Red Hat build of Quarkus) - Affected
Package: shiro-core (Red Hat Fuse 7) - Out of support scope
Package: shiro-core (Red Hat Integration Camel K 1) - Affected
Package: shiro-core (Red Hat Integration Camel Quarkus 1) - Affected
Packa
Debian
CVE-2022-32532: shiro - Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypa...
vendor_debian·2022·CVSS 9.8
CVE-2022-32532 [CRITICAL] CVE-2022-32532: shiro - Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypa...
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Scope: local
bookworm: open
bullseye: open
sid: open
trixie: open
OSV
Improper Authorization in Apache Shiro
osv·2022-06-30
CVE-2022-32532 [CRITICAL] Improper Authorization in Apache Shiro
Improper Authorization in Apache Shiro
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
GHSA
Improper Authorization in Apache Shiro
ghsa·2022-06-30
CVE-2022-32532 [CRITICAL] CWE-285 Improper Authorization in Apache Shiro
Improper Authorization in Apache Shiro
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
OSV
CVE-2022-32532: Apache Shiro before 1
osv·2022-06-29·CVSS 9.8
CVE-2022-32532 [CRITICAL] CVE-2022-32532: Apache Shiro before 1
Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-32532 shiro: authorization bypass due to possible misconfigured
bugzilla·2022-07-14·CVSS 9.8
CVE-2022-32532 [CRITICAL] CVE-2022-32532 shiro: authorization bypass due to possible misconfigured
CVE-2022-32532 shiro: authorization bypass due to possible misconfigured
A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
Reference:
https://www.openwall.com/lists/oss-security/2022/06/28/2
Wiz
CVE-2026-23901 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-23901 [CRITICAL] CVE-2026-23901 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23901 :
Apache Shiro vulnerability analysis and mitigation
Observable Timing Discrepancy vulnerability in Apache Shiro.
This issue affects Apache Shiro: from 1. , 2. before 2.0.7.
Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue.
Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough,
that a brute-force attack may be able to tell, by timing the requests only, determine if
the request failed because of a non-existent user vs. wrong password.
The most likely attack vector is a local attack only.
Shiro security model https://shiro.apache.org/security-model.html#username_enumeration discusses this as well.
Typically, brute force attack can be mitigated at the infrastructure level.
Source : NVD
## 1
Scor
2022-06-29
Published