Lucene search

K
cve[email protected]CVE-2023-46750
HistoryDec 14, 2023 - 9:15 a.m.

CVE-2023-46750

2023-12-1409:15:42
CWE-601
web.nvd.nist.gov
16
apache shiro
cve-2023-46750
url redirection
open redirect
security vulnerability
apache shiro update

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.5%

URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability when “form” authentication is used in Apache Shiro.
Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.

Affected configurations

Vulners
NVD
Node
apacheshiroRange1.13.0
OR
apacheshiroRange2.0.0-alpha-4

CNA Affected

[
  {
    "collectionURL": "https://repo.maven.apache.org/maven2",
    "defaultStatus": "unaffected",
    "packageName": "org.apache.shiro:shiro-web",
    "product": "Apache Shiro",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "1.13.0",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "lessThan": "2.0.0-alpha-4",
        "status": "affected",
        "version": "2.0.0-alpha-1",
        "versionType": "semver"
      }
    ]
  }
]

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.5%