#cwe-304

共收录 5 条相关安全情报。

← 返回所有主题

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. U

💡 风险点: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: 有可用补丁/修复方案 (+3) | Secondary 数据源 (+2) | 包含 CVE (+2) | LLM 评分加成 (+0.4)
CVE-2026-55957

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. U

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-57915

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-44547

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/public/public-user.php by an unrelated PR before any 7.2.x tag was cut. Every shipped 7.2.x release therefore remains exploitable by the PoC published with the original advisory. This vulnerability is fixe

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: CVSS 严重风险 (9.6) (+4) | Primary 数据源 (+3) | LLM 评分加成 (+0.4)
CVE-2026-42452

Termix 是一款基于 Web 的服务端管理平台,提供 SSH 终端、隧道和文件编辑功能。在版本 2.1.0 之前,/users/login 接口为启用了 TOTP 双因素认证(2FA)的账户签发一个临时 JWT(temp_token),该令牌携带 pendingTOTP 状态,本应仅用于第二步认证流程。然而,认证中间件错误地在常规认证端点上接受了这个临时令牌,导致攻击者只要知道密码(第一步因素)就能直接访问需要 2FA 保护的资源,实际上将双因素认证降级为单因素(密码)认证。该漏洞严重影响启用了 TOTP 的账户安全,攻击者可利用泄露的密码绕过第二因素防护。此问题已在 Termix 2.1.0 版本中修复。建议所有用户立即升级至 2.1.0 或更高版本,同时在升级前限制网络暴露面,避免将管理界面直接暴露在公网。

💡 影响/原因: 该漏洞使双因素认证机制完全失效,攻击者仅凭密码即可绕过 TOTP 保护,危害账户安全。CVSS 8.1 评分表明影响严重,需要立即修复。

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)