Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/my0113/shiro-cve-2022-32532
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubmy0113/shiro-cve-2022-32532

shiro-cve-2022-32532

Minimal Java web application to reproduce CVE-2022-32532, an Apache Shiro RegExPatternMatcher authentication bypass via newline characters in URLs.

View Repository
21 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Apache Shiro CVE-2022-32532 Reproduction Environment

This is a minimal web application for reproducing CVE-2022-32532 (Apache Shiro RegExPatternMatcher authentication bypass).

Vulnerability Description

  • CVE: CVE-2022-32532
  • Affected versions: Shiro < 1.9.1
  • Cause: RegExPatternMatcher does not properly anchor regular expressions, which may lead to path bypass. Specifically, it uses Java's default regex matching logic; when encountering the . symbol as a regex, it ignores special characters like \r (%0d) and \n (%0a). It must explicitly use regex matching rules based on the Pattern.DOTALL mode to correctly handle \r and \n characters. Versions below Shiro-1.9.1 all use the default regex matching logic, so they cannot correctly handle \r and \n, leading to authentication bypass.

How to Reproduce

  1. Start the application

    root@kitploit:~
    启动ShiroCve202232532Application
    
    
  2. URL that returns access denied through normal Shiro authentication:
    http://localhost:8080/permit/xxx, the trailing xxx can be replaced with any characters

  3. URL that bypasses Shiro authentication and returns success:
    http://localhost:8080/permit/xxx, i.e., insert newline \n (%0a) or carriage return \r (%0d) in the trailing xxx

  4. Solution

    1. Copy the entire contents of RegExPatternMatcher.java and PatternMatcher.java from https://github.com/apache/shiro/blob/shiro-root-1.9.1/core/src/main/java/org/apache/shiro/util/.
    2. Use JDK 11 to compile these two Java files into RegExPatternMatcher.class and PatternMatcher.class.
    3. Use WinRAR to put these two class files into org/apache/shiro/util/ inside shiro-core-1.6.0.jar.
    4. For the fix test, copy the RegExPatternMatcher.java code from shiro-core-1.9.1 into this case and rename it to RegExPatternMatcher191.java, then change new RegExPatternMatcher() on line 15 of MyFilter and line 29 of MyShiroFilterFactoryBean to new RegExPatternMatcher191().
    5. The implementation logic of RegExPatternMatcher in shiro-core-1.9.1 is as follows:
root@kitploit:~
/*
 * Licensed to the Apache Software Foundation (ASF) under one
 * or more contributor license agreements.  See the NOTICE file
 * distributed with this work for additional information
 * regarding copyright ownership.  The ASF licenses this file
 * to you under the Apache License, Version 2.0 (the
 * "License"); you may not use this file except in compliance
 * with the License.  You may obtain a copy of the License at
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing,
 * software distributed under the License is distributed on an
 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
 * KIND, either express or implied.  See the License for the
 * specific language governing permissions and limitations
 * under the License.
 */
package org.apache.shiro.util;

import java.util.regex.Pattern;
import java.util.regex.Matcher;

/**
 * {@code PatternMatcher} implementation that uses standard {@link java.util.regex} objects.
 *
 * @see Pattern
 * @since 1.0
 */
public class RegExPatternMatcher implements PatternMatcher {

   private static final int DEFAULT = Pattern.DOTALL;

   private static final int CASE_INSENSITIVE = DEFAULT | Pattern.CASE_INSENSITIVE;

   private boolean caseInsensitive = false;

   /**
    * Simple implementation that merely uses the default pattern comparison logic provided by the
    * JDK.
    * <p/>This implementation essentially executes the following:
    * <pre>
    * Pattern p = Pattern.compile(pattern, Pattern.DOTALL);
    * Matcher m = p.matcher(source);
    * return m.matches();</pre>
    * @param pattern the pattern to match against
    * @param source  the source to match
    * @return {@code true} if the source matches the required pattern, {@code false} otherwise.
    */
   public boolean matches(String pattern, String source) {
      if (pattern == null) {
         throw new IllegalArgumentException("pattern argument cannot be null.");
      }
      Pattern p = Pattern.compile(pattern, caseInsensitive ? CASE_INSENSITIVE : DEFAULT);
      Matcher m = p.matcher(source);
      return m.matches();
   }

   /**
    * Returns true if regex match should be case-insensitive.
    * @return true if regex match should be case-insensitive.
    */
   public boolean isCaseInsensitive() {
      return caseInsensitive;
   }

   /**
    * Adds the Pattern.CASE_INSENSITIVE flag when compiling patterns.
    * @param caseInsensitive true if patterns should match case-insensitive.
    */
   public void setCaseInsensitive(boolean caseInsensitive) {
      this.caseInsensitive = caseInsensitive;
   }
}
Download Tool