Pivotal Spring-LDAP CVE-2017-8028 Authentication Bypass Vulnerability
BID:101485
Info
Pivotal Spring-LDAP CVE-2017-8028 Authentication Bypass Vulnerability
| Bugtraq ID: | 101485 |
| Class: | Design Error |
| CVE: |
CVE-2017-8028 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2017 12:00AM |
| Updated: | Oct 16 2017 12:00AM |
| Credit: | Tobias Schneider. |
| Vulnerable: |
Pivotal Spring-LDAP 2.3.1 Pivotal Spring-LDAP 2.3.0 Pivotal Spring-LDAP 1.3.0 |
| Not Vulnerable: |
Pivotal Spring-LDAP 2.3.2 |
Discussion
Pivotal Spring-LDAP CVE-2017-8028 Authentication Bypass Vulnerability
Pivotal Spring-LDAP are prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access. This may lead to further attacks.
Spring-LDAP versions 1.3.0 through 2.3.1 are vulnerable.
Pivotal Spring-LDAP are prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access. This may lead to further attacks.
Spring-LDAP versions 1.3.0 through 2.3.1 are vulnerable.
Exploit / POC
Pivotal Spring-LDAP CVE-2017-8028 Authentication Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].