Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass.
https://github.com/kunFeng1998/CVE-2020-13933Project
https://github.com/advisories/GHSA-2vgm-wxr3-6w2j
https://github.com/XuCcc/VulEnv
https://lists.debian.org/debian-lts-announce/2021/08/msg00002.html