Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1390 |
Tue, 25 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internet2
Internet2 grouper |
|
| CPEs | cpe:2.3:a:internet2:grouper:5.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Internet2
Internet2 grouper |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-27T19:08:16.288Z
Reserved: 2024-06-29T00:00:00.000Z
Link: CVE-2024-39848
Updated: 2024-08-02T04:33:10.226Z
Status : Awaiting Analysis
Published: 2024-06-29T22:15:02.263
Modified: 2025-03-27T20:15:26.860
Link: CVE-2024-39848
No data.
OpenCVE Enrichment
No data.
Weaknesses