Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-11407

Опубликовано: 13 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

not-affected

3.4.15+dfsg-2ubuntu4
devel

not-affected

3.4.15+dfsg-2ubuntu4
disco

not-affected

3.4.15+dfsg-2ubuntu4
eoan

not-affected

3.4.15+dfsg-2ubuntu4
esm-apps/bionic

released

3.4.6+dfsg-1ubuntu0.1+esm1
esm-apps/focal

not-affected

3.4.15+dfsg-2ubuntu4
esm-apps/jammy

not-affected

3.4.15+dfsg-2ubuntu4
esm-apps/xenial

not-affected

Показывать по

EPSS

Процентиль: 42%
0.00198
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.

CVSS3: 9.8
debian
около 7 лет назад

An issue was discovered in the Ldap component in Symfony 2.8.x before ...

CVSS3: 9.8
github
около 3 лет назад

Symfony Authentication Bypass

EPSS

Процентиль: 42%
0.00198
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3