Apache Shiro is a set of Java security frameworks used by the Apache Software Foundation to perform authentication, authorization, encryption and session management. A security vulnerability exists in Apache Shiro versions prior to 1.6.0. An attacker could exploit this vulnerability to bypass authentication with a specially crafted HTTP request. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None