CVE-2024-52316CWE-391

Apache Tomcat: Authentication bypass when using Jakarta Authentication API

Critical · published November 18, 2024

CVSS v3.1
9.8
EPSS
6%
Percentile
93.1
In the wild
Unconfirmed
What it is

🚨 A configuration quirk in Apache Tomcat could let users waltz right past authentication, all because of an unchecked error condition! 🔥 Think of it like a hotel where a guest checks in but the front desk clerk forgets to ask for identification. In this case, the system fails to indicate a failed authentication attempt, so anyone can stroll right in without proper clearance! An attacker could potentially bypass authentication entirely, granting access to sensitive applications or data, which could be absolutely devastating for your system's security! Imagine unauthorized users mingling in your private space, wreaking havoc without any signs of their entry!

Put simply

Think of it like a hotel where a guest checks in but the front desk clerk forgets to ask for identification. In this case, the system fails to indicate a failed authentication attempt, so anyone can stroll right in without proper clearance! This unchecked error condition in Tomcat allows certain custom Jakarta Authentication components to fail silently during authentication, failing to set an appropriate HTTP status when an error occurs. This means that users could bypass authentication without the system recognizing it, posing a significant security risk.

What to do

An attacker could potentially bypass authentication entirely, granting access to sensitive applications or data, which could be absolutely devastating for your system's security! Imagine unauthorized users mingling in your private space, wreaking havoc without any signs of their entry! Upgrade your Apache Tomcat to version 11.0.0, 10.1.31, or 9.0.96 immediately to fix this vulnerability. If you're managing older versions like 8.5.x, consider migrating to supported versions as they are known to be affected and pose a critical risk. You’ve got this! With the right updates in place, your system will be secure again in no time! 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.06246 · 93.1th percentile
Weakness
CWE-391 · Unchecked Error Condition
Published
2024-11-18T11:32Z
EPSS history
Timeline
  • 18 NOV 11:32Z
    Apache Tomcat: Authentication bypass when using Jakarta Authentication API
    cvelistv5