Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11187

Опубликовано: 15 авг. 2019
Источник: debian

Описание

Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fusiondirectoryfixed1.2.3-5package
fusiondirectoryfixed1.2.3-4+deb10u1busterpackage
fusiondirectoryfixed1.0.19-1+deb9u1stretchpackage
gosafixed2.7.4+reloaded3-9package
gosafixed2.7.4+reloaded3-8+deb10u1busterpackage
gosafixed2.7.4+reloaded2-13+deb9u2stretchpackage

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.

CVSS3: 9.8
nvd
больше 6 лет назад

Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.

CVSS3: 9.8
github
больше 3 лет назад

Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.