Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability when "form" authentication is used in Apache Shiro. Mitigation: Update to Apache Shiro 1.13.0+ or 2.0.0-alpha-4+.
Remediation
References
https://lists.apache.org/thread/hoc9zdyzmmrfj1zhctsvvtx844tcq6w9
https://security.netapp.com/advisory/ntap-20240808-0002/
Related Vulnerabilities
CVE-2023-28709 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-29246 Vulnerability in maven package org.apache.openmeetings:openmeetings-install
CVE-2020-2202 Vulnerability in maven package org.jenkins-ci.plugins:fortify-on-demand-uploader
CVE-2010-2076 Vulnerability in maven package org.apache.cxf:cxf-bundle
CVE-2023-39155 Vulnerability in maven package org.jenkins-ci.plugins:chef-identity