In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-http-auth-nginx-module that have enabled basic authentication. This is fixed in version 1.1.1 of spnego-http-auth-nginx-module. As a workaround, one may disable basic authentication.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2021-03-08T20:20:19
Updated: 2024-08-03T18:09:15.422Z
Reserved: 2020-12-22T00:00:00
Link: CVE-2021-21335
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-03-08T21:15:16.573
Modified: 2024-11-21T05:48:02.897
Link: CVE-2021-21335
Redhat
No data.