CVE-2019-11187: Critical severity gosa vulnerability
Published Aug 15, 2019
·Updated
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.
Affected Software
2 affected components
GONICUS GOsa<=2019-04-11
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Aug 15, 2019
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-11187?
CVE-2019-11187 is considered a critical vulnerability due to its potential for unauthorized account access.
2
How do I fix CVE-2019-11187?
To remediate CVE-2019-11187, upgrade GONICUS GOsa to a version released after April 11, 2019.
3
Which software versions are affected by CVE-2019-11187?
CVE-2019-11187 affects GONICUS GOsa versions before 2019-04-11 and Debian GNU/Linux 8.0.
4
Can CVE-2019-11187 be exploited remotely?
Yes, CVE-2019-11187 can be exploited remotely as it allows access with arbitrary passwords for specific usernames.
5
What is the impact of exploiting CVE-2019-11187?
Exploiting CVE-2019-11187 can lead to unauthorized access to user accounts, compromising sensitive information.