Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7m73-q993-vw77

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

EPSS

Процентиль: 91%
0.0728
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

redhat
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

nvd
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.

debian
больше 14 лет назад

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require ...

oracle-oval
больше 14 лет назад

ELSA-2011-0347: openldap security update (MODERATE)

EPSS

Процентиль: 91%
0.0728
Низкий

Дефекты

CWE-287