Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-46750

Опубликовано: 13 дек. 2023
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.

An "Open-Redirect" flaw was found in the Apache Shiro project. This issue may allow remote attackers to redirect legitimate users to arbitrary web sites containing malware that can compromise the user's machine and conduct phishing attacks to steal the user's credentials.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3shiroNot affected
Red Hat build of Apache Camel for Spring Boot 4shiroNot affected
Red Hat build of Quarkusorg.apache.shiro/shiro-coreNot affected
Red Hat Fuse 7shiroOut of support scope
Red Hat Integration Camel K 1shiroWill not fix
Red Hat JBoss Enterprise Application Platform 7shiro-coreNot affected
Red Hat JBoss Enterprise Application Platform 8shiro-coreNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packshiro-coreWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2254478shiro: URL redirection to untrusted site in FORM authentication feature

EPSS

Процентиль: 42%
0.00201
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 2 лет назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.

CVSS3: 6.1
nvd
около 2 лет назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.

CVSS3: 6.1
debian
около 2 лет назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability when ...

CVSS3: 6.1
github
около 2 лет назад

Open redirect in Apache Shiro

EPSS

Процентиль: 42%
0.00201
Низкий

6.1 Medium

CVSS3