Lucene search

K
tomcatApache TomcatTOMCAT:B7EB6B23524A2491A4E8200F0D520A47
HistoryMay 12, 2021 - 12:00 a.m.

Fixed in Apache Tomcat 8.5.66

2021-05-1200:00:00
Apache Tomcat
tomcat.apache.org
52
apache tomcat
8.5.66
authentication weakness
jndi realm
user data
configuration data
vulnerability fix

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

EPSS

0.002

Percentile

58.4%

Low: Authentication weakness CVE-2021-30640

Queries made by the JNDI Realm did not always correctly escape parameters. Parameter values could be sourced from user provided data (eg user names) as well as configuration data provided by an administrator. In limited circumstances it was possible for users to authenticate using variations of their user name and/or to bypass some of the protection provided by the LockOut Realm.

This was fixed with commits 24dfb300, 0a272b00, c9f21a2a, 4e86b4ea, 79580e7f, d3407672, 6a9129ac and ad22db64.

This issue was reported publicly as 65224.

Affects: 8.5.0 to 8.5.65

Affected configurations

Vulners
Node
apachetomcatRange8.5.0
OR
apachetomcatRange8.5.65
VendorProductVersionCPE
apachetomcat*cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

EPSS

0.002

Percentile

58.4%