Lucene search

K
rubygemsRubySecRUBY:LDAP_FLUFF-2012-5604-90579
HistoryDec 03, 2012 - 8:00 p.m.

CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind

2012-12-0320:00:00
RubySec
rubysec.com
6

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

51.2%

The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when
using Active Directory for authentication, allows remote attackers to bypass authentication
via unspecified vectors.

CPENameOperatorVersion
ldap_flufflt0.1.3

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.001 Low

EPSS

Percentile

51.2%

Related for RUBY:LDAP_FLUFF-2012-5604-90579