QID 983473
QID 983473: Java (maven) Security Update for org.apache.shiro:shiro-core (GHSA-r679-m633-g7wc)
Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r679-m633-g7wc for updates pertaining to this vulnerability.
Vendor References
- GHSA-r679-m633-g7wc -
github.com/advisories/GHSA-r679-m633-g7wc
CVEs related to QID 983473
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r679-m633-g7wc | org.apache.shiro:shiro-core |
|