PT-2013-1811 · Ruby+2 · Ldap Fluff+2
Og Maciel
·
Published
2013-03-01
·
Updated
2022-05-14
·
CVE-2012-5604
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ldap fluff gem for Ruby (affected versions not specified)
Red Hat CloudForms version 1.1
Description
The issue allows remote attackers to bypass authentication via unspecified vectors when using Active Directory for authentication.
Recommendations
For Red Hat CloudForms version 1.1, consider disabling the use of Active Directory for authentication until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Active Directory
Red Hat Cloudforms
Ldap Fluff