Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in Apache Shiro - CVE-2026-43828
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to expose sensitive cookie values over an insecure channel.
The vulnerability exists due to improper cookie security attribute configuration in the Shiro-native session manager and Remember-Me manager when sending JSESSIONID and rememberMe cookies in HTTPS sessions. A remote attacker can intercept cookie transmission to expose sensitive cookie values over an insecure channel.
The issue affects cookies that are sent without the Secure attribute by default.