Lucene search

K
osvGoogleOSV:GHSA-4F7H-9J2X-CMR4
HistoryMay 14, 2022 - 1:17 a.m.

Improper Authentication in Apache Tomcat

2022-05-1401:17:03
Google
osv.dev
19
apache tomcat
authentication
http digest access

EPSS

0.002

Percentile

55.4%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qop values, which might allow remote attackers to bypass intended integrity-protection requirements via a qop=auth value, a different vulnerability than CVE-2011-1184.

References