Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5246

Опубликовано: 24 авг. 2015
Источник: redhat
CVSS2: 4.9

Описание

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

Отчет

Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenStack ForemanforemanNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) InstallerforemanNot affected
Red Hat Satellite 6foremanNot affected

Показывать по

Дополнительная информация

https://bugzilla.redhat.com/show_bug.cgi?id=1258700Foreman: previous password still allowed to log into foreman with Active Directory backend

4.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.1
nvd
почти 9 лет назад

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

CVSS3: 8.1
debian
почти 9 лет назад

The LDAP Authentication functionality in Foreman might allow remote at ...

CVSS3: 8.1
github
около 4 лет назад

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

4.9 Medium

CVSS2