Apache Group
------------
Apache Group已经为此发布了一个安全公告(CVE-2023-22602)以及相应补丁:
CVE-2023-22602:CVE-2023-22602: Apache Shiro before 1.11.0, when used with Spring Boot 2.6+, may allow authentication bypass through a specially crafted HTTP request
链接:https://lists.apache.org/thread/dzj0k2smpzzgj6g666hrbrgsrlf9yhkl