Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T04:33:10.226Z
Reserved: 2024-06-29T00:00:00
Link: CVE-2024-39848

Updated: 2024-08-02T04:33:10.226Z

Status : Awaiting Analysis
Published: 2024-06-29T22:15:02.263
Modified: 2024-11-21T09:28:26.230
Link: CVE-2024-39848

No data.