https://seclists.org/oss-sec/2023/q4/275: CVE-2023-46750: Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro.
Published Dec 13, 2023
·Updated
Affected Software
2 affected components
Apache Shiro<1.13.0
Apache Shiro<2.0.0-alpha-4
Frequently Asked Questions
1
What is the severity of CVE-2023-46750?
CVE-2023-46750 has a moderate severity rating.
2
Which versions of Apache Shiro are affected by CVE-2023-46750?
Apache Shiro versions before 1.13.0 and 2.0.0-alpha-1 before 2.0.0-alpha-4 are affected by CVE-2023-46750.
3
What type of vulnerability is CVE-2023-46750?
CVE-2023-46750 is a URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the FORM authentication feature.
4
How do I fix CVE-2023-46750?
To fix CVE-2023-46750, update Apache Shiro to version 1.13.0 or later, or to 2.0.0-alpha-4 or later.
5
When was CVE-2023-46750 published?
CVE-2023-46750 was published on December 13, 2023.