PT-2014-6050 · Cherokee · Cherokee

Matthew Daley

·

Publicado

2014-07-02

·

Atualizado

2017-01-03

·

CVE-2014-4668

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cherokee versions 1.2.103 and earlier
Description The issue concerns the cherokee validator ldap check function in validator ldap.c. When LDAP is used, it does not properly consider unauthenticated-bind semantics. This allows remote attackers to bypass authentication by using an empty password.
Recommendations For Cherokee versions 1.2.103 and earlier, consider disabling the LDAP authentication mechanism until a patch is available. Restrict access to the cherokee validator ldap check function to minimize the risk of exploitation. Avoid using empty passwords in the affected LDAP configuration until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-4668
MGASA-2015-0181

Produtos afetados

Cherokee