PT-2020-7943 · Node-Krb5 · Node-Krb5
Published
2020-09-01
·
Updated
2020-09-01
·
CVE-2016-1000238
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
node-krb5 (affected versions not specified)
Description:
The issue concerns the lack of validation of the KDC prior to authentication in affected versions, potentially allowing an attacker with network access to spoof the KDC and impersonate a valid user without knowing their credentials.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a mitigation measure, consider using an alternative module that is actively maintained and provides similar functionality.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Node-Krb5