Vulnerability Database

289,571

Total vulnerabilities in the database

CVE-2024-52316

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95.

Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue.

No technical information available.

CWEs:

Software From Fixed in
apache / tomcat 11.0.0-milestone1 11.0.0-milestone1.x
apache / tomcat 11.0.0-milestone2 11.0.0-milestone2.x
apache / tomcat 11.0.0-milestone4 11.0.0-milestone4.x
apache / tomcat 11.0.0-milestone3 11.0.0-milestone3.x
apache / tomcat 11.0.0-milestone5 11.0.0-milestone5.x
apache / tomcat 11.0.0-milestone7 11.0.0-milestone7.x
apache / tomcat 11.0.0-milestone10 11.0.0-milestone10.x
apache / tomcat 11.0.0-milestone11 11.0.0-milestone11.x
apache / tomcat 11.0.0-milestone12 11.0.0-milestone12.x
apache / tomcat 11.0.0-milestone13 11.0.0-milestone13.x
apache / tomcat 11.0.0-milestone14 11.0.0-milestone14.x
apache / tomcat 11.0.0-milestone15 11.0.0-milestone15.x
apache / tomcat 11.0.0-milestone16 11.0.0-milestone16.x
apache / tomcat 11.0.0-milestone17 11.0.0-milestone17.x
apache / tomcat 11.0.0-milestone18 11.0.0-milestone18.x
apache / tomcat 11.0.0-milestone6 11.0.0-milestone6.x
apache / tomcat 11.0.0-milestone8 11.0.0-milestone8.x
apache / tomcat 11.0.0-milestone9 11.0.0-milestone9.x
apache / tomcat 9.0.0 9.0.96
apache / tomcat 10.1.0 10.1.31
apache / tomcat 11.0.0-milestone19 11.0.0-milestone19.x
apache / tomcat 11.0.0-milestone20 11.0.0-milestone20.x
apache / tomcat 11.0.0-milestone21 11.0.0-milestone21.x
apache / tomcat 11.0.0-milestone22 11.0.0-milestone22.x
apache / tomcat 11.0.0-milestone23 11.0.0-milestone23.x
apache / tomcat 11.0.0-milestone24 11.0.0-milestone24.x
apache / tomcat 11.0.0-milestone25 11.0.0-milestone25.x
apache / tomcat 11.0.0-milestone26 11.0.0-milestone26.x