Описание
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| esm-apps-legacy/xenial | not-affected | see notes |
| esm-apps/xenial | ignored | end of ESM support, was needed |
| esm-infra-legacy/trusty | needed | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE | |
| impish | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-apps-legacy/xenial | needed | |
| esm-apps/bionic | not-affected | see notes |
| esm-apps/xenial | ignored | end of ESM support, was needed |
| esm-infra-legacy/trusty | needed | |
| esm-infra/focal | DNE | |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needs-triage |
| devel | DNE | |
| esm-apps/bionic | needed | |
| esm-infra-legacy/trusty | DNE | |
| esm-infra-legacy/xenial | needed | |
| esm-infra/focal | DNE | |
| esm-infra/xenial | ignored | end of ESM support, was needed |
| focal | DNE | |
| groovy | DNE | |
| hirsute | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 9.0.16-3ubuntu0.18.04.2 |
| devel | not-affected | 9.0.46 |
| esm-apps/bionic | released | 9.0.16-3ubuntu0.18.04.2 |
| esm-apps/focal | released | 9.0.31-1ubuntu0.2 |
| esm-apps/jammy | not-affected | 9.0.46 |
| esm-apps/noble | not-affected | 9.0.46 |
| esm-apps/resolute | not-affected | 9.0.46 |
| esm-infra-legacy/trusty | DNE | |
| focal | released | 9.0.31-1ubuntu0.2 |
| groovy | ignored | end of life |
Показывать по
Ссылки на источники
5.8 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker ...
Authentication Bypass by Alternate Name in Apache Tomcat
Уязвимость реализации модуля JNDIRealm сервера приложений Apache Tomcat, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
5.8 Medium
CVSS2
6.5 Medium
CVSS3