-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability centers on unvalidated redirects via the targetURI parameter during authentication flows. While exact patch details are unavailable, the advisory explicitly states the attack vector and mitigation approach (enforcing relative URLs). In Java web applications, authentication success handlers and security filters are common locations for redirect logic. The identified functions align with Ambari's package structure and security handling patterns. High confidence in AmbariSessionManager as it directly manages session-related redirects, medium confidence in AuthenticationFilter as a common security component handling post-auth flows.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.ambari:ambari | maven | >= 1.7.0, < 2.1.2 | 2.1.2 |
Ongoing coverage of React2Shell