PT-2019-12173 · Gonicus+1 · Gosa+1

Published

2019-08-10

·

Updated

2020-10-28

·

CVE-2019-11187

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GONICUS GOsa through 2019-04-11
Description The issue allows an attacker to bypass access controls by logging into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided. This is due to an incorrect access control in the LDAP class.
Recommendations For GONICUS GOsa through 2019-04-11, update to a version released after 2019-04-11 to resolve the issue. As a temporary workaround, consider restricting access to the LDAP class to minimize the risk of exploitation. Avoid using usernames containing the substring "success" in the affected system until the issue is resolved.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11187
DLA-1875-1
DLA-1876-1
USN-4609-1

Affected Products

Gosa
Ubuntu