Authentication Bypass by Alternate Name in Apache Tomcat
Moderate severity
GitHub Reviewed
Published
Aug 13, 2021
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Package
Affected versions
>= 10.0.0-M1, < 10.0.5
>= 9.0.0M1, < 9.0.45
>= 8.5.0, < 8.5.65
Patched versions
10.0.5
9.0.45
8.5.65
Description
Published by the National Vulnerability Database
Jul 12, 2021
Reviewed
Jul 13, 2021
Published to the GitHub Advisory Database
Aug 13, 2021
Last updated
Feb 3, 2023
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
References