High
Apache Shiro could allow a remote attacker to execute arbitrary code on the system, caused by the use of a default cipher key for the “remember me” feature. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system or obtain sensitive information.
Apache
Apache Shiro 1.0.0
Apache Shiro 1.1.0
Apache Shiro 1.2.0
Apache Shiro 1.2.1
Upgrade to the latest version of Shiro, available from the Apache Web site.