CVE-2021-30640: Auth weakness in JNDIRealm
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
Other sources
Apache Tomcat could allow a remote attacker to bypass security restrictions, caused by improper authentication validation in the JNDI Realm. By sending a specially-crafted request using various user names, an attacker could exploit this vulnerability to bypass some of the protection provided by the LockOut Realm.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-30640?
CVE-2021-30640 is a vulnerability in the JNDI Realm of Apache Tomcat that allows an attacker to bypass security restrictions.
How does CVE-2021-30640 impact Apache Tomcat?
CVE-2021-30640 allows a remote attacker to bypass security restrictions in Apache Tomcat.
What is the severity of CVE-2021-30640?
CVE-2021-30640 has a severity rating of 7.5 (high).
Which versions of Apache Tomcat are affected by CVE-2021-30640?
Affected versions include Apache Tomcat 7.0.0 to 7.0.109, 8.5.0 to 8.5.66, 9.0.0 to 9.0.46, and 10.0.0 to 10.0.6.
How can I fix CVE-2021-30640 in Apache Tomcat?
To fix CVE-2021-30640, upgrade to Apache Tomcat versions 7.0.110, 8.5.67, 9.0.47, or 10.0.7.