cherokee: authentication bypass
| Package(s): | cherokee | CVE #(s): | CVE-2014-4668 | ||||||||||||||||
| Created: | April 27, 2015 | Updated: | May 5, 2015 | ||||||||||||||||
| Description: | From the CVE entry:
The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
