Graylog2 CVE-2014-9217 LDAP Authentication Bypass Vulnerability
BID:71827
Info
Graylog2 CVE-2014-9217 LDAP Authentication Bypass Vulnerability
| Bugtraq ID: | 71827 |
| Class: | Design Error |
| CVE: |
CVE-2014-9217 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2014 12:00AM |
| Updated: | Dec 22 2014 12:00AM |
| Credit: | José Tozo |
| Vulnerable: |
Torch GmbH Graylog2 0.91.3 |
| Not Vulnerable: |
Torch GmbH Graylog2 0.92 |
Discussion
Graylog2 CVE-2014-9217 LDAP Authentication Bypass Vulnerability
Graylog2 is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Versions prior to Graylog2 0.92 are vulnerable.
Graylog2 is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Versions prior to Graylog2 0.92 are vulnerable.
Exploit / POC
Graylog2 CVE-2014-9217 LDAP Authentication Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Graylog2 CVE-2014-9217 LDAP Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Graylog2 CVE-2014-9217 LDAP Authentication Bypass Vulnerability
References:
References:
- Graylog2 - 0.92 version release (Torch GmbH)
- Graylog2 - Homepage (Torch GmbH)