cbcvebase.
CVE-2023-46750
published 2023-12-14

CVE-2023-46750: URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.

Affected

7 ranges
VendorProductVersion rangeFixed in
apacheshiro< 1.13.01.13.0
apacheshiro
apacheshiro>= 0 < 1.2.4-1ubuntu0.1~esm21.2.4-1ubuntu0.1~esm2
apacheshiro>= 0 < 1.3.2-5ubuntu0.24.04.1~esm11.3.2-5ubuntu0.24.04.1~esm1
apache_software_foundationapache_shiro< 1.13.01.13.0
apache_software_foundationapache_shiro>= 2.0.0-alpha-1 < 2.0.0-alpha-42.0.0-alpha-4
debianshiro

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv7.5HIGH