6.8
CVSSv2

CVE-2014-4668

Published: 02/07/2014 Updated: 03/01/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and previous versions, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote malicious users to bypass authentication via an empty password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 21

fedoraproject fedora 20

fedoraproject fedora 22

mageia project mageia 4

cherokee-project cherokee 1.2.98

cherokee-project cherokee 1.2.2

cherokee-project cherokee 1.2.101

cherokee-project cherokee 1.2.99

cherokee-project cherokee

cherokee-project cherokee 1.2.102