Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with . in the regular expression are possibly vulnerable to an authorization bypass.
.
{ "binaries": [ { "binary_version": "1.3.2-5", "binary_name": "libshiro-java" } ] }
{ "binaries": [ { "binary_version": "1.3.2-6ubuntu1", "binary_name": "libshiro-java" } ] }
{ "binaries": [ { "binary_version": "1.2.4-1ubuntu0.1~esm2", "binary_name": "libshiro-java" } ] }
{ "binaries": [ { "binary_version": "1.3.2-3ubuntu0.18.04.1~esm1", "binary_name": "libshiro-java" } ] }
{ "binaries": [ { "binary_version": "1.3.2-4ubuntu0.2", "binary_name": "libshiro-java" } ] }