Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.
{
"severity": "CRITICAL",
"github_reviewed_at": "2022-07-06T19:52:31Z",
"nvd_published_at": "2022-06-29T00:15:00Z",
"cwe_ids": [
"CWE-285",
"CWE-863"
],
"github_reviewed": true
}