OWASP ESAPI CBC Mode HMAC Authentication Bypass Vulnerability
BID:62415
Info
OWASP ESAPI CBC Mode HMAC Authentication Bypass Vulnerability
| Bugtraq ID: | 62415 |
| Class: | Design Error |
| CVE: |
CVE-2013-5679 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 15 2013 12:00AM |
| Updated: | Apr 16 2015 06:04PM |
| Credit: | Philippe Arteau |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OWASP ESAPI CBC Mode HMAC Authentication Bypass Vulnerability
OWASP ESAPI is prone to an authentication-bypass vulnerability.
Local attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
ESAPI 2.0GA and 2.0.1 are vulnerable.
OWASP ESAPI is prone to an authentication-bypass vulnerability.
Local attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
ESAPI 2.0GA and 2.0.1 are vulnerable.
Exploit / POC
OWASP ESAPI CBC Mode HMAC Authentication Bypass Vulnerability
The researcher has created a functional exploit to demonstrate the issue. Please see the references for more information.
The researcher has created a functional exploit to demonstrate the issue. Please see the references for more information.
Solution / Fix
OWASP ESAPI CBC Mode HMAC Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OWASP ESAPI CBC Mode HMAC Authentication Bypass Vulnerability
References:
References: