PT-2019-12173 · Gonicus+1 · Gosa+1
Published
2019-08-10
·
Updated
2020-10-28
·
CVE-2019-11187
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GONICUS GOsa through 2019-04-11
Description
The issue allows an attacker to bypass access controls by logging into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided. This is due to an incorrect access control in the LDAP class.
Recommendations
For GONICUS GOsa through 2019-04-11, update to a version released after 2019-04-11 to resolve the issue. As a temporary workaround, consider restricting access to the LDAP class to minimize the risk of exploitation. Avoid using usernames containing the substring "success" in the affected system until the issue is resolved.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gosa
Ubuntu