VYPR

Spnego HTTP Authentication Module

by Spnego HTTP Authentication Module Project

CVEs (1)

  • CVE-2021-21335MedMar 8, 2021
    risk 0.00cvss 5.3epss 0.02

    In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentication can be bypassed using a malformed username. This affects users of spnego-http-auth-nginx-module that have enabled basic authentication. This is fixed in…