Bug 2539354 (CVE-2026-75973)
| Summary: | CVE-2026-75973 tomcat: Apache Tomcat: Cross-context authentication mix-up via Jakarta Authentication misconfiguration | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | csutherl, dsoumis, jclere, jwon, pjindal, plodge, rhel-process-autobot, rmaucher, szappis, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Apache Tomcat. When Jakarta Authentication is configured with SimpleAuthConfigProvider as the default provider and multiple web applications utilize it, an improper authentication vulnerability arises. This issue causes the authentication realm established for the first web application to be incorrectly applied to all subsequent web applications. Consequently, this could lead to unauthorized access or incorrect authorization decisions across different web applications.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2543044 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-23 11:33:12 UTC
|