PT-2020-7943 · Node-Krb5 · Node-Krb5

Published

2020-09-01

·

Updated

2020-09-01

·

CVE-2016-1000238

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: node-krb5 (affected versions not specified)
Description: The issue concerns the lack of validation of the KDC prior to authentication in affected versions, potentially allowing an attacker with network access to spoof the KDC and impersonate a valid user without knowing their credentials.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a mitigation measure, consider using an alternative module that is actively maintained and provides similar functionality.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-1000238
GHSA-4V9Q-HM2P-68C4

Affected Products

Node-Krb5