Lucene search

K
osvGoogleOSV:GHSA-JGM2-M5CG-F66G
HistoryMay 17, 2022 - 12:59 a.m.

Authentication Bypass in Apache Tomcat

2022-05-1700:59:04
Google
osv.dev
11

0.003 Low

EPSS

Percentile

69.2%

org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placing /j_security_check at the end of a URI.

References