CVE-2022-40664
CRITICALApache Shiro < 1.10.0 - Authentication Bypass via RequestDispatcher
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-40664. PoCs published by JAckLosingHeart.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2022-40664, an authentication bypass vulnerability in Apache Shiro. The exploit demonstrates how an attacker can bypass Shiro's URL-based access control by manipulating request paths and forwarding requests to protected endpoints.
Description
Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.
Exploits (1)
This repository contains a functional proof-of-concept for CVE-2022-40664, an authentication bypass vulnerability in Apache Shiro. The exploit demonstrates how an attacker can bypass Shiro's URL-based access control by manipulating request paths and forwarding requests to protected endpoints.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H