PT-2014-8719 · Dokuwiki · Dokuwiki
Splitbrain
·
Publicado
2014-10-22
·
Atualizado
2016-07-15
·
CVE-2014-8764
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
DokuWiki versions 2014-05-05a and earlier
Description
The issue allows remote attackers to bypass authentication when using Active Directory for LDAP authentication. This is achieved by providing a user name and password starting with a null (0) character, which triggers an anonymous bind.
Recommendations
For versions 2014-05-05a and earlier, consider disabling the use of Active Directory for LDAP authentication until a fix is available. As a temporary workaround, restrict access to the LDAP authentication module to minimize the risk of exploitation.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dokuwiki