We found results for “”
CVE-2024-39848
Good to know:
Date: June 28, 2024
Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Weak Authentication
CWE-1390Top Fix
Upgrade Version
Upgrade to version edu.internet2.middleware.grouper:grouper-ws:5.6.0;edu.internet2.middleware.grouper:grouper-ws:4.14.1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


