Bug 1072603 (CVE-2014-0074)

Summary: CVE-2014-0074 Apache Shiro: successful authentication without specifying user name or password
Product: [Other] Security Response Reporter: Martin Prpič <mprpic>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: chazlett, djorm, jrusnack, kconner, soa-p-jira, weli
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
It was discovered that Apache Shiro authenticated users without specifying a user name or a password when used in conjunction with an LDAP back end that allowed unauthenticated binds.
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-10-09 18:24:51 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1059445, 1072760, 1113315    

Description Martin Prpič 2014-03-04 21:23:16 UTC
It was discovered [1] that Apache Shiro authenticated users without specifying a user name or a password when used in conjunction with an LDAP back end that allowed unauthenticated binds.

This issue has been fixed upstream in version 1.2.3 of Apache Shiro.

[1] https://issues.apache.org/jira/browse/SHIRO-460
[2] http://seclists.org/fulldisclosure/2014/Mar/22

Comment 2 David Jorm 2014-03-18 01:02:00 UTC
Upstream patch commit:

http://svn.apache.org/viewvc?view=revision&revision=1572813

Comment 4 Martin Prpič 2014-09-29 11:58:05 UTC
IssueDescription:

It was discovered that Apache Shiro authenticated users without specifying a user name or a password when used in conjunction with an LDAP back end that allowed unauthenticated binds.

Comment 5 errata-xmlrpc 2014-10-01 18:10:47 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Fuse/A-MQ 6.1.0

Via RHSA-2014:1351 https://rhn.redhat.com/errata/RHSA-2014-1351.html

Comment 6 errata-xmlrpc 2014-10-09 16:07:57 UTC
This issue has been addressed in the following products:

  Fuse ESB Enterprise 7.1.0
  Fuse MQ Enterprise 7.1.0

Via RHSA-2014:1369 https://rhn.redhat.com/errata/RHSA-2014-1369.html