Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.
{ "binaries": [ { "binary_name": "libshiro-java", "binary_version": "1.2.4-1ubuntu0.1~esm2" } ] }
{ "binaries": [ { "binary_name": "libshiro-java", "binary_version": "1.3.2-3ubuntu0.18.04.1~esm1" } ] }
{ "binaries": [ { "binary_name": "libshiro-java", "binary_version": "1.3.2-4ubuntu0.2" } ] }
{ "binaries": [ { "binary_name": "libshiro-java", "binary_version": "1.3.2-5" } ] }