Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-6802
- https://github.com/apache/shiro/commit/b15ab927709ca18ea4a02538be01919a19ab65af
- https://issues.apache.org/jira/browse/SHIRO-584
- https://packetstormsecurity.com/files/138709/Apache-Shiro-Filter-Bypass.html
- https://github.com/advisories/GHSA-4q2v-j639-cp7p