Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.
Update org.apache.shiro:shiro-core to 2.2.0; org.apache.shiro:shiro-core to 3.0.0-alpha-2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Shiro has a session fixation vulnerability affects org.apache.shiro:shiro-core (maven), org.apache.shiro:shiro-core (maven). Severity is medium. Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.shiro:shiro-coremaven | >=1.0.0-incubating,<2.2.0 |
Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.
Update org.apache.shiro:shiro-core to 2.2.0; org.apache.shiro:shiro-core to 3.0.0-alpha-2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Shiro has a session fixation vulnerability affects org.apache.shiro:shiro-core (maven), org.apache.shiro:shiro-core (maven). Severity is medium. Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.shiro:shiro-coremaven | >=1.0.0-incubating,<2.2.0 |
| 2.2.0 |
| org.apache.shiro:shiro-coremaven | =3.0.0-alpha-1 | 3.0.0-alpha-2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 2.2.0 |
| org.apache.shiro:shiro-coremaven | =3.0.0-alpha-1 | 3.0.0-alpha-2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard