Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-552j-r9hx-pgwr

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.

EPSS

Процентиль: 77%
0.01011
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 18 лет назад

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.

EPSS

Процентиль: 77%
0.01011
Низкий

Дефекты

CWE-287