Описание
The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:jens_vagelpohl:zope-ldapuserfolder:2.9-1:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00539
Низкий
7.5 High
CVSS2
Дефекты
CWE-287
Связанные уязвимости
ubuntu
больше 15 лет назад
The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges.
debian
больше 15 лет назад
The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope- ...
github
больше 3 лет назад
The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges.
EPSS
Процентиль: 67%
0.00539
Низкий
7.5 High
CVSS2
Дефекты
CWE-287