Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
Update org.apache.shiro:shiro-jakarta-ee to 2.2.1; org.apache.shiro:shiro-jakarta-ee to 3.0.0-alpha-2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login affects org.apache.shiro:shiro-jakarta-ee (maven), org.apache.shiro:shiro-jakarta-ee (maven). Severity is low. Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
AI coding agents often install or upgrade packages automatically in maven. A low vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.shiro:shiro-jakarta-ee |
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
Update org.apache.shiro:shiro-jakarta-ee to 2.2.1; org.apache.shiro:shiro-jakarta-ee to 3.0.0-alpha-2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login affects org.apache.shiro:shiro-jakarta-ee (maven), org.apache.shiro:shiro-jakarta-ee (maven). Severity is low. Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to influence the redirect target in applications using the Jakarta EE module. This issue affects Apache Shiro from 2.0-alpha to 2.2.0, and 3.0.0-alpha-1, only when using shiro-jakarta-ee integration module.
AI coding agents often install or upgrade packages automatically in maven. A low vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.shiro:shiro-jakarta-ee |
| >=2.0-alpha,<2.2.1 |
| 2.2.1 |
| org.apache.shiro:shiro-jakarta-eemaven | >=3.0.0-alpha-0,<3.0.0-alpha-2 | 3.0.0-alpha-2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=2.0-alpha,<2.2.1 |
| 2.2.1 |
| org.apache.shiro:shiro-jakarta-eemaven | >=3.0.0-alpha-0,<3.0.0-alpha-2 | 3.0.0-alpha-2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard