Bug 2254478 (CVE-2023-46750) - CVE-2023-46750 shiro: URL redirection to untrusted site in FORM authentication feature
Summary: CVE-2023-46750 shiro: URL redirection to untrusted site in FORM authenticatio...
Keywords:
Status: NEW
Alias: CVE-2023-46750
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2254482
TreeView+ depends on / blocked
 
Reported: 2023-12-14 07:02 UTC by TEJ RATHI
Modified: 2024-07-20 08:28 UTC (History)
50 users (show)

Fixed In Version: apache-shiro 1.13.0, apache-shiro 2.0.0-alpha-4
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description TEJ RATHI 2023-12-14 07:02:27 UTC
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro.

Affected versions:

- Apache Shiro before 1.13.0
- Apache Shiro 2.0.0-alpha-1 before 2.0.0-alpha-4

https://issues.apache.org/jira/browse/OFBIZ-12866
https://lists.apache.org/thread/ff0rq7rykh6zxb7l4dronowpoxrcqkr8
https://seclists.org/oss-sec/2023/q4/275
https://www.mail-archive.com/notifications@ofbiz.apache.org/msg52244.html


Note You need to log in before you can comment on or make changes to this bug.