CVE-2023-46750
published 2023-12-14CVE-2023-46750: URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.50%
71.2th percentile
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro.
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shiro | < 1.13.0 | 1.13.0 |
| apache | shiro | — | — |
| apache | shiro | >= 0 < 1.2.4-1ubuntu0.1~esm2 | 1.2.4-1ubuntu0.1~esm2 |
| apache | shiro | >= 0 < 1.3.2-5ubuntu0.24.04.1~esm1 | 1.3.2-5ubuntu0.24.04.1~esm1 |
| apache_software_foundation | apache_shiro | < 1.13.0 | 1.13.0 |
| apache_software_foundation | apache_shiro | >= 2.0.0-alpha-1 < 2.0.0-alpha-4 | 2.0.0-alpha-4 |
| debian | shiro | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Shiro vulnerabilities
vendor_ubuntu·2024-12-10·CVSS 7.5
CVE-2023-34478 [HIGH] Apache Shiro vulnerabilities
Title: Apache Shiro vulnerabilities
Summary: Several security issues were fixed in Apache Shiro.
It was discovered that Apache Shiro incorrectly handled path traversal when
used with other web frameworks or path rewriting. An attacker could
possibly use this issue to obtain sensitive information or administrative
privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749)
It was discovered that Apache Shiro incorrectly handled web redirects when
used together with the form authentication method. An attacker could
possibly use this issue to perform phishing attacks. This update provides
the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2023-46750)
It was discovered that Apache Shiro incorrectly handled re
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache Shiro) — CVE-2023-46750
vendor_oracle·2024-07-15·CVSS 6.1
CVE-2023-46750 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache Shiro) — CVE-2023-46750
Oracle Oracle Fusion Middleware Risk Matrix: WebCenter Sites (Apache Shiro) vulnerability
CVE: CVE-2023-46750
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Red Hat
shiro: URL redirection to untrusted site in FORM authentication feature
vendor_redhat·2023-12-13·CVSS 6.1
CVE-2023-46750 [MEDIUM] CWE-601 shiro: URL redirection to untrusted site in FORM authentication feature
shiro: URL redirection to untrusted site in FORM authentication feature
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro.
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
An "Open-Redirect" flaw was found in the Apache Shiro project. This issue may allow remote attackers to redirect legitimate users to arbitrary web sites containing malware that can compromise the user's machine and conduct phishing attacks to steal the user's credentials.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: shiro (Red Hat bu
Debian
CVE-2023-46750: shiro - URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" au...
vendor_debian·2023·CVSS 6.1
CVE-2023-46750 [MEDIUM] CVE-2023-46750: shiro - URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" au...
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
Scope: local
bookworm: open
bullseye: open
sid: open
trixie: open
OSV
shiro vulnerabilities
osv·2024-12-10·CVSS 7.5
CVE-2023-34478 [HIGH] shiro vulnerabilities
shiro vulnerabilities
It was discovered that Apache Shiro incorrectly handled path traversal when
used with other web frameworks or path rewriting. An attacker could
possibly use this issue to obtain sensitive information or administrative
privileges. This update provides the corresponding fix for Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2023-34478, CVE-2023-46749)
It was discovered that Apache Shiro incorrectly handled web redirects when
used together with the form authentication method. An attacker could
possibly use this issue to perform phishing attacks. This update provides
the corresponding fix for Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2023-46750)
It was discovered that Apache Shiro incorrectly handled requests through
servlet filtering. An attacker could possibly use this issue
OSV
Open redirect in Apache Shiro
osv·2023-12-14
CVE-2023-46750 [MEDIUM] Open redirect in Apache Shiro
Open redirect in Apache Shiro
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro.
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
GHSA
Open redirect in Apache Shiro
ghsa·2023-12-14
CVE-2023-46750 [MEDIUM] CWE-601 Open redirect in Apache Shiro
Open redirect in Apache Shiro
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro.
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
OSV
CVE-2023-46750: URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro
osv·2023-12-14·CVSS 6.1
CVE-2023-46750 [MEDIUM] CVE-2023-46750: URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
No detection rules found.
No public exploits indexed.
2023-12-14
Published