Cherokee CVE-2014-4668 Authentication Bypass Vulnerability
BID:68249
Info
Cherokee CVE-2014-4668 Authentication Bypass Vulnerability
| Bugtraq ID: | 68249 |
| Class: | Design Error |
| CVE: |
CVE-2014-4668 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2014 12:00AM |
| Updated: | May 12 2015 07:41PM |
| Credit: | Matthew Daley |
| Vulnerable: |
Cherokee Cherokee 1.2.99 |
| Not Vulnerable: | |
Discussion
Cherokee CVE-2014-4668 Authentication Bypass Vulnerability
Cherokee is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Cherokee 1.2.103 and prior are vulnerable.
Cherokee is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Cherokee 1.2.103 and prior are vulnerable.
Exploit / POC
Cherokee CVE-2014-4668 Authentication Bypass Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Cherokee CVE-2014-4668 Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cherokee CVE-2014-4668 Authentication Bypass Vulnerability
References:
References: