4.3
CVE-2012-4494
- EPSS 1.08%
- Veröffentlicht 31.10.2012 16:55:03
- Zuletzt bearbeitet 16.06.2026 23:45:12
- Erkennungen
The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibly have other impacts by logging in.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Niif ≫ Shibb Auth Version 7.x-4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.08% | 0.608 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://www.openwall.com/lists/oss-security/2012/10/04/6
http://www.openwall.com/lists/oss-security/2012/10/07/1
http://drupal.org/node/1719392
http://drupal.org/node/1493244
http://drupalcode.org/project/shib_auth.git/commitdiff/2032f0a