CWE-592
24 CVEs • Abstraction: Class
DEPRECATED: Authentication Bypass Issues
This weakness has been deprecated because it covered redundant concepts already described in CWE-287.
CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9...Show more |
Gotham Gaia application was found to be exposing multiple unauthenticated endpoints. |
An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint. |
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnJun 17, 2026 Jan 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized informatio...Show more |
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if inv...Show more |
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted. |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Aug 14, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, an...Show more |
2Redhat Theforeman2Foreman Tasks SatelliteJun 17, 2026 Jul 31, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an un...Show more |
2Heketi Project Redhat2Heketi Openshift Container PlatformJun 17, 2026 Apr 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3....Show more |
1Baxter 1Sigma Spectrum Infusion System Firmware Nov 21, 2024 Mar 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A remote attacker may be able to make unaut...Show more |
6Canonical DebianLibssh+3 more9Debian Linux Enterprise LinuxLibssh+6 moreNov 21, 2024 Oct 17, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access. |
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instan...Show more |
A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with...Show more |
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authentic...Show more |
1Jenkins 1Pipeline Classpath Step Nov 21, 2024 Jul 27, 2018 N/A· v4 8.5 HIGH· v3 6.0 MEDIUM· v2 It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permission in Jenkins. |
1Gnome 1Gnome Display Manager Nov 21, 2024 Jul 26, 2018 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock...Show more |
2Dogtagpki Redhat4Dogtagpki Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular auth...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jun 15, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled. Quotations around the values of ETCD_CLIENT_CERT_AUTH and ETCD_PEER...Show more |
1Phoenixcontact 1Ilc Plcs Firmware Nov 21, 2024 Apr 5, 2018 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled. |