CVE-2023-46750

Source
https://cve.org/CVERecord?id=CVE-2023-46750
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-46750.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-46750
Aliases
Downstream
Published
2023-12-14T08:15:58.031Z
Modified
2026-05-18T05:57:09.303052595Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N CVSS Calculator
Summary
Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.
Details

URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46750.json",
    "cna_assigner": "apache",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "1.13.0"
                },
                {
                    "introduced": "2.0.0-alpha-1"
                },
                {
                    "fixed": "2.0.0-alpha-4"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-601"
    ]
}
References

Affected packages

Git / github.com/apache/shiro

Affected ranges

Type
GIT
Repo
https://github.com/apache/shiro
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "CPE_FIELD",
    "cpe": "cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.13.0"
        }
    ]
}

Affected versions

shiro-root-1.*
shiro-root-1.10.0
shiro-root-1.10.0-vote-1
shiro-root-1.11.0
shiro-root-1.13.0-vote-1
shiro-root-1.4.0-RC2
shiro-root-1.4.0-RC2-release-vote1
shiro-root-1.4.1
shiro-root-1.5.0
shiro-root-1.5.2
shiro-root-1.5.2-release-vote1
shiro-root-1.5.3
shiro-root-1.5.3-release-vote1
shiro-root-1.6.0
shiro-root-1.7.0
shiro-root-1.7.1
shiro-root-1.8.0
shiro-root-1.9.0
shiro-root-1.9.0-release-vote1
shiro-root-1.9.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-46750.json"