USN-7139-1: Apache Shiro vulnerability
5 December 2024
Apache Shiro could be made to run programs or expose sensitive information over the network.
Releases
Packages
- shiro - Powerful and easy-to-use Java security framework
Details
It was discovered that Apache Shiro used a static cipher within the
"Remember Me" feature inside authentication by default. An attacker could
possibly use this issue to achieve remote code execution or obtain
sensitive information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
libshiro-java
-
1.2.4-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.