Gitblit External Authentication Providers Unspecified Authentication Bypass Vulnerability
BID:66324
Info
Gitblit External Authentication Providers Unspecified Authentication Bypass Vulnerability
| Bugtraq ID: | 66324 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2014 12:00AM |
| Updated: | Mar 17 2014 12:00AM |
| Credit: | shumal.av |
| Vulnerable: |
Gitblit Gitblit 0.9.1 Gitblit Gitblit 0.7 Gitblit Gitblit 0.6.9 Gitblit Gitblit 1.4.0 |
| Not Vulnerable: |
Gitblit Gitblit 1.4.1 |
Discussion
Gitblit External Authentication Providers Unspecified Authentication Bypass Vulnerability
Gitblit is prone to a remote unspecified authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Versions prior to Gitblit 1.4.1 are vulnerable.
Gitblit is prone to a remote unspecified authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Versions prior to Gitblit 1.4.1 are vulnerable.
Exploit / POC
Gitblit External Authentication Providers Unspecified Authentication Bypass Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Gitblit External Authentication Providers Unspecified Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Gitblit External Authentication Providers Unspecified Authentication Bypass Vulnerability
References:
References:
- Current Release (1.4.1) (Gitblit)
- Gitblit Homepage (Gitblit)
- Successfull login into Gitblit again under valid Redmine login and invalid passw (shumal.av)