First published: Wed Jul 02 2014(Updated: )
The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject Fedora | =20 | |
Fedoraproject Fedora | =21 | |
Fedoraproject Fedora | =22 | |
Mageia Project Mageia | =4 | |
Cherokee-project Cherokee | <=1.2.103 | |
Cherokee-project Cherokee | =1.2.2 | |
Cherokee-project Cherokee | =1.2.98 | |
Cherokee-project Cherokee | =1.2.99 | |
Cherokee-project Cherokee | =1.2.101 | |
Cherokee-project Cherokee | =1.2.102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.