CVE-2023-22602 is an authentication bypass vulnerability affecting Apache Shiro versions prior to 1.11.0 when used with Spring Boot 2.6 or newer. This flaw arises from differing pattern-matching techniques between Shiro and Spring Boot, allowing a specially crafted HTTP request to bypass authentication. Rated 7.5 HIGH, this vulnerability has a low attack complexity and can lead to high integrity impact, though it does not affect confidentiality or availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, organizations should update to Shiro 1.11.0 or configure Spring Boot to use 'ant_path_matcher' as a mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11.0CPE matchmatch criteria | cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:a:vmware:spring_boot:2.6.0:\+:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.