Описание
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login.
In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module.
This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
A flaw was found in Apache Shiro's Jakarta EE module. Insufficient validation of the HTTP Referer header, a client-controlled value, could allow an attacker to influence the redirect target after a user login. This vulnerability can be exploited to redirect users to malicious sites, potentially leading to phishing attacks or other security bypasses.
Отчет
Red Hat ships Apache Shiro's Jakarta EE integration module (shiro-jakarta-ee) as a bundled dependency in EAP XP. A flaw was found where insufficient validation of the HTTP Referer header could allow an attacker to influence the redirect target after user login, potentially redirecting users to malicious sites. This vulnerability only affects applications using the shiro-jakarta-ee module specifically, not Apache Shiro core.
Меры по смягчению последствий
Ensure that applications using Apache Shiro's Jakarta EE module do not rely solely on the HTTP Referer header for post-login redirect decisions. Where possible, configure explicit redirect URLs in the application rather than accepting client-supplied values.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform Expansion Pack | shiro-jakarta-ee | Fix deferred |
Показывать по
Дополнительная информация
Статус:
4.6 Medium
CVSS3
Связанные уязвимости
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
Apache Shiro\u2019s Jakarta EE module used the HTTP Referer header in ...
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login
4.6 Medium
CVSS3