Executive brief
Apache Shiro, a security framework for Java applications, contains a flaw in its Jakarta EE integration module. An attacker with valid login credentials can manipulate a specific browser cookie to redirect users to malicious websites or force the server to make unauthorized internal requests. This could lead to the exposure of internal network information or phishing attacks against users.
Technical details
A vulnerability exists in the Apache Shiro Jakarta EE integration module where the 'shiroSavedRequest' cookie is not properly validated. After a successful login, the application uses this cookie to determine the redirection target. An authenticated attacker can forge this cookie to perform an Open Redirect or trigger a Server-Side Request Forgery (SSRF) via an HTTP GET request initiated by the server. The vulnerability is present in versions 2.0-alpha through 2.1.0 and 3.0.0-alpha-1. The fix, introduced in versions 2.2.0 and 3.0.0-alpha-2, involves encrypting the cookie to prevent tampering.
Affected products
- Apache Software Foundation Shiro Jakarta EE module 2.0.0-alpha-0 to 2.1.0, 3.0.0-alpha-1
Timeline
- 2026-05-25: disclosed: Initial disclosure by Apache Software Foundation
- 2026-05-26: advisory: GitHub Advisory published