← Back to CVE List

CVE-2021-21335

Published: 2021-03-08T21:15Z
Last Modified: 2024-11-21T05:48Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-http-auth-nginx-module that have enabled basic authentication. This is fixed in version 1.1.1 of spnego-http-auth-nginx-module. As a workaround, one may disable basic authentication. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt