URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Affected versions: - Apache Shiro before 1.13.0 - Apache Shiro 2.0.0-alpha-1 before 2.0.0-alpha-4 https://issues.apache.org/jira/browse/OFBIZ-12866 https://lists.apache.org/thread/ff0rq7rykh6zxb7l4dronowpoxrcqkr8 https://seclists.org/oss-sec/2023/q4/275 https://www.mail-archive.com/notifications@ofbiz.apache.org/msg52244.html