Executive brief
Central Dogma, a repository service for configuration and assets, contains a vulnerability in its login function when using Shiro authentication. An attacker can create a malicious link that, when clicked by a user, redirects them from the legitimate service to a fraudulent phishing website. This can be used to steal user credentials and gain unauthorized access to the organization's configuration data.
Technical details
An open redirect vulnerability (CWE-601) exists in Central Dogma's login functionality when configured with Shiro authentication. The application fails to properly validate user-controlled input used in redirection after a login attempt. A remote, unauthenticated attacker can exploit this by crafting a URL that specifies an external, malicious destination. If a victim clicks this link and interacts with the login page, they are redirected to the attacker-controlled site. This is typically used to conduct phishing attacks to harvest credentials. The issue is resolved in version 0.78.0 by improving how the login service handles redirection logic.
Affected products
- LINE Corporation centraldogma-server-auth-shiro < 0.78.0
Timeline
- 2025-11-14: patched: Fix merged into main branch
- 2025-12-04: disclosed: Advisory published by LINE Corporation
- 2025-12-04: advisory