CyberRota Analysis
AI-GeneratedApache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.0.M1 through 9.0.120 are vulnerable due to an improper authentication flaw that allows users to be authenticated without existing in the DataSourceRealm, particularly in scenarios involving CLIENT-CERT and SPNEGO. This vulnerability could lead to unauthorized access, making it critical for organizations using affected versions to prioritize upgrading to 11.0.25, 10.1.58, or 9.0.121 to mitigate potential security risks. Users of older, unsupported versions (8.5.x and 7.0.x) should also take immediate action to address this vulnerability.
Original NVD Description
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)