Apache Kerby是美国Apache基金会的一款Kerberos认证协议实现框架。 Apache Kerby 2.1.2之前版本存在授权问题漏洞,该漏洞源于发送未识别或不受支持的PA-DATA类型可绕过Kerberos预身份验证检查。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Kerby | < 2.1.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Kerby | 0 ~ 2.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49486 | Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT | |
| CVE-2026-57914 | Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures | |
| CVE-2025-55017 | Apache IoTDB: Path Traversal Vulnerability | |
| CVE-2025-64152 | Apache IoTDB: Path Traversal Vulnerability |
No comments yet