Miggo Logo

CVE-2021-30640: Authentication Bypass by Alternate Name in Apache Tomcat

6.5

CVSS Score
3.1

Basic Information

EPSS Score
0.40087%
Published
8/13/2021
Updated
2/3/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.apache.tomcat:tomcatmaven>= 10.0.0-M1, < 10.0.510.0.5
org.apache.tomcat:tomcatmaven>= 9.0.0M1, < 9.0.459.0.45
org.apache.tomcat:tomcatmaven>= 8.5.0, < 8.5.658.5.65

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

* vuln*r**ility in t** JN*I R**lm o* *p**** Tom**t *llows *n *tt**k*r to *ut**nti**t* usin* v*ri*tions o* * v*li* us*r n*m* *n*/or to *yp*ss som* o* t** prot**tion provi*** *y t** Lo*kOut R**lm. T*is issu* *****ts *p**** Tom**t **.*.*-M* to **.*.*; *

Reasoning

No *n*lysis *v*il**l*