Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
shiro-cve-2022-32532 — Aplicação web Java mínima para reproduzir o CVE-2022-32532, um bypass de autenticação do Apache Shiro RegExPatternMatcher através de caracteres de nova linha em URLs. | Kitploit
Ferramentas/GitHubGitHub/my0113/shiro-cve-2022-32532
Autenticação e AutorizaçãoAnálise de VulnerabilidadesExploraçãoExploração de Aplicações WebTestes de PenetraçãoAprendizado e Educação
GitHubmy0113/shiro-cve-2022-32532

shiro-cve-2022-32532

Aplicação web Java mínima para reproduzir o CVE-2022-32532, um bypass de autenticação do Apache Shiro RegExPatternMatcher através de caracteres de nova linha em URLs.

Ver Repositório
9há 1 anoAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

Ambiente de Reprodução do Apache Shiro CVE-2022-32532

Este é um aplicativo web mínimo para reproduzir o CVE-2022-32532 (bypass de autenticação do Apache Shiro RegExPatternMatcher).

Descrição da Vulnerabilidade

  • CVE: CVE-2022-32532
  • Versões afetadas: Shiro < 1.9.1
  • Causa: RegExPatternMatcher não ancora corretamente as expressões regulares, o que pode levar a bypass de caminho. Especificamente, utiliza a lógica de correspondência de expressões regulares padrão do Java. Quando o símbolo . é usado como expressão regular, ele ignora caracteres especiais como \r (%0d) e \n (%0a). É necessário usar explicitamente o modo de correspondência baseado em Pattern.DOTALL para processar corretamente os símbolos \r e \n. Versões anteriores ao Shiro 1.9.1 usam a lógica de correspondência padrão, portanto não conseguem processar \r e \n corretamente, resultando em bypass de autenticação.

Como Reproduzir

  1. Inicie a aplicação

    启动ShiroCve202232532Application
    
    
  2. URL que retorna access denied com autenticação normal do Shiro:
    http://localhost:8080/permit/xxx, o xxx final pode ser substituído por qualquer caractere.

  3. URL que contorna a autenticação do Shiro e retorna success:
    http://localhost:8080/permit/xxx, ou seja, insira uma quebra de linha \n (%0a) e um retorno de carro \r (%0d) no xxx final.

  4. Solução

    1. Copie todo o conteúdo de RegExPatternMatcher.java e PatternMatcher.java de https://github.com/apache/shiro/blob/shiro-root-1.9.1/core/src/main/java/org/apache/shiro/util/
    2. Compile esses dois arquivos Java com JDK 11 para obter RegExPatternMatcher.class e PatternMatcher.class.
    3. Use o WinRAR para colocar esses 2 arquivos .class em shiro-core-1.6.0.jar, dentro de org/apache/shiro/util/.
    4. No teste de correção, o código de RegExPatternMatcher.java do shiro-core-1.9.1 foi copiado para este caso e renomeado para RegExPatternMatcher191.java, então altere new RegExPatternMatcher() na linha 15 do MyFilter e na linha 29 do MyShiroFilterFactoryBean para new RegExPatternMatcher191().
    5. A lógica de implementação do RegExPatternMatcher no shiro-core-1.9.1 é a seguinte:
/*
 * Licensed to the Apache Software Foundation (ASF) under one
 * or more contributor license agreements.  See the NOTICE file
 * distributed with this work for additional information
 * regarding copyright ownership.  The ASF licenses this file
 * to you under the Apache License, Version 2.0 (the
 * "License"); you may not use this file except in compliance
 * with the License.  You may obtain a copy of the License at
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing,
 * software distributed under the License is distributed on an
 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
 * KIND, either express or implied.  See the License for the
 * specific language governing permissions and limitations
 * under the License.
 */
package org.apache.shiro.util;

import java.util.regex.Pattern;
import java.util.regex.Matcher;

/**
 * {@code PatternMatcher} implementation that uses standard {@link java.util.regex} objects.
 *
 * @see Pattern
 * @since 1.0
 */
public class RegExPatternMatcher implements PatternMatcher {

   private static final int DEFAULT = Pattern.DOTALL;

   private static final int CASE_INSENSITIVE = DEFAULT | Pattern.CASE_INSENSITIVE;

   private boolean caseInsensitive = false;

   /**
    * Simple implementation that merely uses the default pattern comparison logic provided by the
    * JDK.
    * <p/>This implementation essentially executes the following:
    * <pre>
    * Pattern p = Pattern.compile(pattern, Pattern.DOTALL);
    * Matcher m = p.matcher(source);
    * return m.matches();</pre>
    * @param pattern the pattern to match against
    * @param source  the source to match
    * @return {@code true} if the source matches the required pattern, {@code false} otherwise.
    */
   public boolean matches(String pattern, String source) {
      if (pattern == null) {
         throw new IllegalArgumentException("pattern argument cannot be null.");
      }
      Pattern p = Pattern.compile(pattern, caseInsensitive ? CASE_INSENSITIVE : DEFAULT);
      Matcher m = p.matcher(source);
      return m.matches();
   }

   /**
    * Returns true if regex match should be case-insensitive.
    * @return true if regex match should be case-insensitive.
    */
   public boolean isCaseInsensitive() {
      return caseInsensitive;
   }

   /**
    * Adds the Pattern.CASE_INSENSITIVE flag when compiling patterns.
    * @param caseInsensitive true if patterns should match case-insensitive.
    */
   public void setCaseInsensitive(boolean caseInsensitive) {
      this.caseInsensitive = caseInsensitive;
   }
}
Baixar ferramenta