Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h5f5-rj4r-42f6

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Incorrect access control in Neo4j Enterprise Database Server via LDAP authentication

Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.

Пакеты

Наименование

org.neo4j:neo4j-enterprise

maven
Затронутые версииВерсия исправления

>= 3.4.0, < 3.4.9

3.4.9

EPSS

Процентиль: 73%
0.00764
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.

EPSS

Процентиль: 73%
0.00764
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287