CVE-2024-39848 : INTERNET2 GROUPER/GROUPER FOR WEB SERVICES LDAP AUTHENTICATION IMPROPER AUTHENTICATION

Description

Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects “Grouper for Web Services” before 4.13.1.

References

https://spaces.at.internet2.edu/display/Grouper/Grouper+bug+-+GRP-5515+-+web+services+LDAP+authentication+security+vulnerability

For More Information

CVERecord

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-39891 : TWILIO AUTHY ON ANDROID/IOS API IMPROPER AUTHENTICATION

CVE-2024-39891 : TWILIO AUTHY ON ANDROID/IOS API IMPROPER AUTHENTICATION

Description In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint

CVE-2022-30636 : X-CRYPTO PRIOR 0.0.0-20220525230936-793AD666BF5E ON GO PATH TRAVERSAL

CVE-2022-30636 : X-CRYPTO PRIOR 0.0.0-20220525230936-793AD666BF5E ON GO PATH TRAVERSAL

Description httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base

CVE-2023-24531 : CMD-GO UP TO 1.20.X ON GO SPECIAL ELEMENT

CVE-2023-24531 : CMD-GO UP TO 1.20.X ON GO SPECIAL ELEMENT

Description Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn’t sanitize