Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
https://github.com/wyqsgy/vulnark
https://github.com/advisories/GHSA-26gr-cvq3-qxgf
https://lists.debian.org/debian-lts-announce/2020/04/msg00014.html