High
CVE-2023-22602
Apache Shiro could allow a remote attacker to bypass security restrictions, caused by a flaw when Shiro and Spring Boot are using different pattern-matching techniques. By sending a specially-crafted HTTP request, an attacker could exploit this vulnerability to bypass access restrictions.
Apache
Upgrade to the latest version of Apache Shiro, available from the Apache Web site.