CVE-2022-40664
published 2022-10-12CVE-2022-40664: Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.21%
80.6th percentile
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.10.0 | 1.10.0 |
| apache_software_foundation | apache_shiro | >= Apache Shiro < 1.10.0 | 1.10.0 |
| debian | shiro | — | — |
| paloalto | pan-os | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Authentication bypass occurs specifically when forwarding or including requests via RequestDispatcher in Apache Shiro before 1.10.0 ↗
- →The vulnerability is remotely exploitable over HTTP, making it detectable via network-level monitoring of HTTP traffic targeting affected Shiro-protected endpoints ↗
- ·Vulnerability only affects Apache Shiro versions before 1.10.0; upgrade to 1.10.0 or later to remediate ↗
- ·Red Hat packages of shiro-core in several products are confirmed Not Affected; only Red Hat Fuse 7 and legacy JBoss Fuse/Fuse Service Works are in scope (out of support) ↗
- ·Debian bookworm, bullseye, sid, and trixie all remain open/unpatched per the security tracker ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2010-1622 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache Shiro) — CVE-2022-40664
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2022-40664 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache Shiro) — CVE-2022-40664
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache Shiro) vulnerability
CVE: CVE-2022-40664
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
shiro: Authentication Bypass Vulnerability
vendor_redhat·2022-10-12·CVSS 9.8
CVE-2022-40664 [CRITICAL] CWE-287 shiro: Authentication Bypass Vulnerability
shiro: Authentication Bypass Vulnerability
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
A flaw was found in Apache Shiro. An authentication bypass vulnerability occurs when forwarding or including via the RequestDispatcher.
Package: shiro-core (Red Hat build of Apache Camel for Spring Boot 3) - Not affected
Package: shiro-core (Red Hat Fuse 7) - Out of support scope
Package: shiro-core (Red Hat Integration Camel K 1) - Not affected
Package: shiro-core (Red Hat Integration Camel Quarkus 2) - Not affected
Package: shiro-core (Red Hat JBoss Enterprise Application Platform 7) - Not affected
Package: shiro-core (Red Hat JBoss Enterprise Application Platform 8) - Not affected
Package: shiro-core (Red Hat JBo
Debian
CVE-2022-40664: shiro - Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when fo...
vendor_debian·2022·CVSS 9.8
CVE-2022-40664 [CRITICAL] CVE-2022-40664: shiro - Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when fo...
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
Scope: local
bookworm: open
bullseye: open
sid: open
trixie: open
GHSA
Apache Shiro Authentication Bypass vulnerability
ghsa·2022-10-12
CVE-2022-40664 [CRITICAL] CWE-287 Apache Shiro Authentication Bypass vulnerability
Apache Shiro Authentication Bypass vulnerability
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
OSV
CVE-2022-40664: Apache Shiro before 1
osv·2022-10-12·CVSS 9.8
CVE-2022-40664 [CRITICAL] CVE-2022-40664: Apache Shiro before 1
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
OSV
Apache Shiro Authentication Bypass vulnerability
osv·2022-10-12
CVE-2022-40664 [CRITICAL] Apache Shiro Authentication Bypass vulnerability
Apache Shiro Authentication Bypass vulnerability
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/10/12/1http://www.openwall.com/lists/oss-security/2022/10/12/2http://www.openwall.com/lists/oss-security/2022/10/13/1https://lists.apache.org/thread/loc2ktxng32xpy7lfwxto13k4lvnhjwghttps://security.netapp.com/advisory/ntap-20221118-0005/http://www.openwall.com/lists/oss-security/2022/10/12/1http://www.openwall.com/lists/oss-security/2022/10/12/2http://www.openwall.com/lists/oss-security/2022/10/13/1https://lists.apache.org/thread/loc2ktxng32xpy7lfwxto13k4lvnhjwghttps://security.netapp.com/advisory/ntap-20221118-0005/
2022-10-12
Published