Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48589

Опубликовано: 25 мая 2026
Источник: redhat
CVSS3: 4.6

Описание

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.

A flaw was found in Apache Shiro's Jakarta EE module. Insufficient validation of the HTTP Referer header, a client-controlled value, could allow an attacker to influence the redirect target after a user login. This vulnerability can be exploited to redirect users to malicious sites, potentially leading to phishing attacks or other security bypasses.

Отчет

Red Hat ships Apache Shiro's Jakarta EE integration module (shiro-jakarta-ee) as a bundled dependency in EAP XP. A flaw was found where insufficient validation of the HTTP Referer header could allow an attacker to influence the redirect target after user login, potentially redirecting users to malicious sites. This vulnerability only affects applications using the shiro-jakarta-ee module specifically, not Apache Shiro core.

Меры по смягчению последствий

Ensure that applications using Apache Shiro's Jakarta EE module do not rely solely on the HTTP Referer header for post-login redirect decisions. Where possible, configure explicit redirect URLs in the application rather than accepting client-supplied values.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform Expansion Packshiro-jakarta-eeFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2481295apache-shiro: shiro-jakarta-ee: Apache Shiro Jakarta EE module: Open Redirect via insufficient HTTP Referer header validation

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
2 месяца назад

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.

CVSS3: 5.4
nvd
2 месяца назад

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.

CVSS3: 5.4
debian
2 месяца назад

Apache Shiro\u2019s Jakarta EE module used the HTTP Referer header in ...

CVSS3: 5.4
github
2 месяца назад

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login

4.6 Medium

CVSS3