URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
2023-12-14T09:15:42.107
2025-05-22T18:15:27.123
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | shiro | < 1.13.0 | Yes |
Application | apache | shiro | 2.0.0 | Yes |
Application | apache | shiro | 2.0.0 | Yes |
Application | apache | shiro | 2.0.0 | Yes |