Lucene search

K
cvelistMitreCVELIST:CVE-2014-4668
HistoryJul 02, 2014 - 1:00 a.m.

CVE-2014-4668

2014-07-0201:00:00
mitre
www.cve.org
4

AI Score

6.6

Confidence

Low

EPSS

0.018

Percentile

88.1%

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.

AI Score

6.6

Confidence

Low

EPSS

0.018

Percentile

88.1%