Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14623

Опубликовано: 24 авг. 2017
Источник: redhat
CVSS3: 5.6

Описание

In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application using this package if these conditions are met: (1) it relies only on the return error of the Bind function call to determine whether a user is authorized (i.e., a nil return value is interpreted as successful authorization) and (2) it is used with an LDAP server allowing unauthenticated bind.

Отчет

This issues affects the version of go-ldap/ldap with Red Hat OpenShift Container Platform (OCP) 3.11. However OpenShift explicitly checks for blank passwords in order to prevent anonymous LDAP binds. As the OpenShift 3.11 product packages the vulnerable library, it is affected, but is set to wontfix. Red Hat Product Security has rated this issue as having security impact of Moderate. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. The 'oc cli' in OCP 3.11 and 4.x also contains the vulnerable go-ldap/ldap library. However, while the oc binary does allow anonymous binds any unauthenticated binds are not possible. Hence the oc cli is marked affected (as it includes the library), but is set to wontfix - this may be addressed in a future release.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11atomic-openshift-clientsWill not fix
Red Hat OpenShift Container Platform 3.11openshift3/ose-cliWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-cliWill not fix
Red Hat OpenShift Container Platform 4openshift-clientsWill not fix
Red Hat OpenShift Enterprise 3atomic-openshiftWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1493998gopkg.in-ldap.v2: Authentication bypass via empty password

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 9 лет назад

In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application using this package if these conditions are met: (1) it relies only on the return error of the Bind function call to determine whether a user is authorized (i.e., a nil return value is interpreted as successful authorization) and (2) it is used with an LDAP server allowing unauthenticated bind.

CVSS3: 8.1
nvd
почти 9 лет назад

In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application using this package if these conditions are met: (1) it relies only on the return error of the Bind function call to determine whether a user is authorized (i.e., a nil return value is interpreted as successful authorization) and (2) it is used with an LDAP server allowing unauthenticated bind.

CVSS3: 8.1
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 8.1
debian
почти 9 лет назад

In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker ...

CVSS3: 8.1
github
больше 4 лет назад

Access Restriction Bypass in go-ldap

5.6 Medium

CVSS3