Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1072603 - (CVE-2014-0074) CVE-2014-0074 Apache Shiro: successful authentication without specifying user name or password
CVE-2014-0074 Apache Shiro: successful authentication without specifying user...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20140304,repo...
: Security
Depends On:
Blocks: 1059445 1072760 1113315
  Show dependency treegraph
 
Reported: 2014-03-04 16:23 EST by Martin Prpič
Modified: 2015-07-31 03:16 EDT (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that Apache Shiro authenticated users without specifying a user name or a password when used in conjunction with an LDAP back end that allowed unauthenticated binds.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-10-09 14:24:51 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:1351 normal SHIPPED_LIVE Important: Red Hat JBoss Fuse/A-MQ 6.1.0 security update 2014-10-01 18:10:39 EDT
Red Hat Product Errata RHSA-2014:1369 normal SHIPPED_LIVE Important: Fuse ESB Enterprise/Fuse MQ Enterprise 7.1.0 update 2014-10-09 16:07:39 EDT

  None (edit)
Description Martin Prpič 2014-03-04 16:23:16 EST
It was discovered [1] that Apache Shiro authenticated users without specifying a user name or a password when used in conjunction with an LDAP back end that allowed unauthenticated binds.

This issue has been fixed upstream in version 1.2.3 of Apache Shiro.

[1] https://issues.apache.org/jira/browse/SHIRO-460
[2] http://seclists.org/fulldisclosure/2014/Mar/22
Comment 2 David Jorm 2014-03-17 21:02:00 EDT
Upstream patch commit:

http://svn.apache.org/viewvc?view=revision&revision=1572813
Comment 4 Martin Prpič 2014-09-29 07:58:05 EDT
IssueDescription:

It was discovered that Apache Shiro authenticated users without specifying a user name or a password when used in conjunction with an LDAP back end that allowed unauthenticated binds.
Comment 5 errata-xmlrpc 2014-10-01 14:10:47 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Fuse/A-MQ 6.1.0

Via RHSA-2014:1351 https://rhn.redhat.com/errata/RHSA-2014-1351.html
Comment 6 errata-xmlrpc 2014-10-09 12:07:57 EDT
This issue has been addressed in the following products:

  Fuse ESB Enterprise 7.1.0
  Fuse MQ Enterprise 7.1.0

Via RHSA-2014:1369 https://rhn.redhat.com/errata/RHSA-2014-1369.html

Note You need to log in before you can comment on or make changes to this bug.