Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whg4-vj5j-j9x2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.

EPSS

Процентиль: 75%
0.00866
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.

CVSS3: 9.8
debian
около 5 лет назад

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG En ...

EPSS

Процентиль: 75%
0.00866
Низкий

Дефекты

CWE-287