4.3
CVE-2012-4494
- EPSS 1.08%
- Veröffentlicht 31.10.2012 16:55:03
- Zuletzt bearbeitet 16.06.2026 23:45:12
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibly have other impacts by logging in.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Niif ≫ Shibb Auth Version7.x-4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.08% | 0.608 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://www.openwall.com/lists/oss-security/2012/10/04/6
http://www.openwall.com/lists/oss-security/2012/10/07/1
http://drupal.org/node/1719392
http://drupal.org/node/1493244
http://drupalcode.org/project/shib_auth.git/commitdiff/2032f0a