Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache…
apache·CWE-614·Published 2026-05-25