Published by Lenny Primak on the
The Apache Shiro team is pleased to announce the release of Apache Shiro version 3.0.1.
This release is available for download now.
This is a maintenance release that includes several security enhancements and bug fixes. It is recommended that all users upgrade to this version.
Case-insensitive filters are now the default for programmatic and Spring / Spring Boot configurations
RememberMe deserialization has been hardened
Guice and AOP annotation retrieval has been improved to prevent potential security issues
Active Directory DN authentication has been fixed to prevent potential security issues
Jakarta EE form resubmit security has been enhanced
Many other hardening and security improvements have been made throughout the framework
You can learn more on GitHub, Release 3.0.1.
Download and verification instructions are available on our download page.