Lucene search

K
tomcatApache TomcatTOMCAT:AAAFF92A877D76F23F91AFEA545747C7
HistoryMay 12, 2021 - 12:00 a.m.

Fixed in Apache Tomcat 10.0.6

2021-05-1200:00:00
Apache Tomcat
tomcat.apache.org
25
apache tomcat
authentication weakness
jndi realm
parameter escaping
user authentication
lockout realm
vulnerability fix
cve-2021-30640
bug 65224

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

EPSS

0.002

Percentile

58.4%

Low: Authentication weakness CVE-2021-30640

Queries made by the JNDI Realm did not always correctly escape parameters. Parameter values could be sourced from user provided data (eg user names) as well as configuration data provided by an administrator. In limited circumstances it was possible for users to authenticate using variations of their user name and/or to bypass some of the protection provided by the LockOut Realm.

This was fixed with commits f4d9bdef, 4e61e1d6, d5303a50, b930d0b3, 17208c64, bd4d1fbe, 81f16b0a and eeb73512.

This issue was reported publicly as 65224.

Affects: 10.0.0-M1 to 10.0.5

Affected configurations

Vulners
Node
apachetomcatRange10.0.0-M1
OR
apachetomcatRange10.0.5
VendorProductVersionCPE
apachetomcat*cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

EPSS

0.002

Percentile

58.4%