Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T04:33:10.226Z

Reserved: 2024-06-29T00:00:00

Link: CVE-2024-39848

cve-icon Vulnrichment

Updated: 2024-08-02T04:33:10.226Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-29T22:15:02.263

Modified: 2024-11-21T09:28:26.230

Link: CVE-2024-39848

cve-icon Redhat

No data.