Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
Update org.apache.shiro:shiro-web to 2.2.0; org.apache.shiro:shiro-web to 3.0.0-alpha-2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute affects org.apache.shiro:shiro-web (maven), org.apache.shiro:shiro-web (maven). Severity is medium. Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.shiro:shiro-webmaven |
Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
Update org.apache.shiro:shiro-web to 2.2.0; org.apache.shiro:shiro-web to 3.0.0-alpha-2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute affects org.apache.shiro:shiro-web (maven), org.apache.shiro:shiro-web (maven). Severity is medium. Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, Shiro-native session manager, as well as Remember-Me manager sends JSESSIONID and rememberMe cookies without 'secure' attribute by default.
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.shiro:shiro-webmaven |
| >=1.0.0-incubating,<2.2.0 |
| 2.2.0 |
| org.apache.shiro:shiro-webmaven | =3.0.0-alpha-1 | 3.0.0-alpha-2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=1.0.0-incubating,<2.2.0 |
| 2.2.0 |
| org.apache.shiro:shiro-webmaven | =3.0.0-alpha-1 | 3.0.0-alpha-2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard