QID 996333
Date Published: 2023-12-18
QID 996333: Java (Maven) Security Update for org.apache.shiro:shiro-web (GHSA-hhw5-c326-822h)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-hhw5-c326-822h for updates and patch information.
Vendor References
- GHSA-hhw5-c326-822h -
github.com/advisories/GHSA-hhw5-c326-822h
CVEs related to QID 996333
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hhw5-c326-822h | org.apache.shiro:shiro-web |
|