← Back to browse · API

CVE-2022-40664

Severity
CRITICAL
CVSS
9.8
EPSS
0.02565
Risk score
40.1
CISA KEV
No
PoC
No
Published
2022-10-12
Modified
2025-05-15
First seen
2026-08-07
Aliases
EUVD-2022-7009, GHSA-45X9-Q6VJ-CQGQ
Products
Apache Software Foundation:Apache Shiro Apache Shiro <1.10.0
Sources
euvd EUVD-2022-7009

Description

Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

References