6.8

CVE-2014-4668

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.

Data is provided by the National Vulnerability Database (NVD)
FedoraprojectFedora Version20
FedoraprojectFedora Version21
FedoraprojectFedora Version22
Mageia ProjectMageia Version4
Cherokee-projectCherokee Version <= 1.2.103
Cherokee-projectCherokee Version1.2.2
Cherokee-projectCherokee Version1.2.98
Cherokee-projectCherokee Version1.2.99
Cherokee-projectCherokee Version1.2.101
Cherokee-projectCherokee Version1.2.102
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.6% 0.688
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.