CVE-2023-22602

CVSS V2 None CVSS V3 None
Description
When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching. Mitigation: Update to Apache Shiro 1.11.0, or set the following Spring Boot configuration value: `spring.mvc.pathmatch.matching-strategy = ant_path_matcher`
Overview
  • CVE ID
  • CVE-2023-22602
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-14T10:15:09
  • Last Modified Date
  • 2023-01-27T15:57:34
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:* 1 AND 1.11.0
cpe:2.3:a:vmware:spring_boot:2.6.0:\+:*:*:*:*:*:* 1 AND
History
Created Old Value New Value Data Type Notes
2023-01-14 11:14:51 Added to TrackCVE
2023-01-14 11:14:52 Weakness Enumeration new
2023-01-17 14:14:54 2023-01-17T13:24:51 CVE Modified Date updated
2023-01-17 14:14:54 Received Awaiting Analysis Vulnerability Status updated
2023-01-20 15:14:52 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-27 16:15:41 2023-01-27T15:57:34 CVE Modified Date updated
2023-01-27 16:15:41 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-27 16:15:43 CPE Information updated