CVE-2023-46750: Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.
Published Dec 13, 2023
·Updated
Apache Shiro could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability when "form" authentication is used. An attacker could exploit this vulnerability using a specially crafted URL to redirect a victim to arbitrary Web sites.
Other sources
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
— MITRE
Affected Software
9 affected componentsFixes available
IBM Cognos Analytics<=12.0.0-12.0.2
IBM Cognos Analytics<=11.2.0-11.2.4 FP3
debian/shiro<=1.3.2-4+deb11u1, <=1.3.2-5
Apache Shiro<1.13.0
Apache Shiro=2.0.0-alpha1
Apache Shiro=2.0.0-alpha2
Apache Shiro=2.0.0-alpha3
maven/org.apache.shiro:shiro-web>=2.0.0-alpha-1<2.0.0-alpha-4
2.0.0-alpha-4
maven/org.apache.shiro:shiro-web<1.13.0
1.13.0
Event History
Dec 14, 2023
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionWeakness
Advisory Published
via GitHub·09:30 AM
Data Sourced
via GitHub·09:30 AM
DescriptionSeverityWeaknessAffected Software
Dec 10, 2024
Data Sourced
via Launchpad·08:12 PM
Description
Dec 14, 2024
Data Sourced
via Ubuntu·08:11 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-46750 vulnerability?
CVE-2023-46750 is an 'Open Redirect' vulnerability in Apache Shiro that allows for URL redirection to untrusted sites when 'form' authentication is used.
2
How can I mitigate CVE-2023-46750 vulnerability?
To mitigate CVE-2023-46750, update to Apache Shiro version 1.13.0 or 2.0.0-alpha-4 or higher.