It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
https://lists.apache.org/thread/1y3glgh3kzwoxo5m2lq504cjlh1dsrfh