Uploaded image for project: 'Geronimo'
  1. Geronimo
  2. GERONIMO-3543

SQLLoginModule successfully authenticates non-existent users

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Critical
    • Resolution: Fixed
    • 2.0, 2.0.1, 2.0.2, 2.1
    • 2.0.3, 2.1
    • security
    • Security Level: public (Regular issues)
    • None
    • Patch Available
    • Regression

    Description

      Authentication succeeds with SQLLoginModule if logging in with an username that does not exist in the database.

      Attachments

        1. GERONIMO-3543.patch
          3 kB
          Vamsavardhana Reddy

        Activity

          People

            vamsic Vamsavardhana Reddy
            gawor@mcs.anl.gov Jarek Gawor
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: