CVE-2024-39848

Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.
Configurations

No configuration.

History

27 Mar 2025, 20:15

Type Values Removed Values Added
CWE CWE-1390

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://spaces.at.internet2.edu/display/Grouper/Grouper+bug+-+GRP-5515+-+web+services+LDAP+authentication+security+vulnerability - () https://spaces.at.internet2.edu/display/Grouper/Grouper+bug+-+GRP-5515+-+web+services+LDAP+authentication+security+vulnerability -

03 Jul 2024, 02:05

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

01 Jul 2024, 12:37

Type Values Removed Values Added
Summary
  • (es) Internet2 Grouper anterior a 5.6 permite omitir la autenticación cuando la autenticación LDAP se utiliza de ciertas maneras. Esto está relacionado con internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication y el uso de la contraseña UyY29r para la cuenta M3vwHr. Esto también afecta a "Grouper for Web Services" anteriores a 4.13.1.

29 Jun 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-29 22:15

Updated : 2025-03-27 20:15


NVD link : CVE-2024-39848

Mitre link : CVE-2024-39848

CVE.ORG link : CVE-2024-39848


JSON object : View

Products Affected

No product.

CWE
CWE-1390

Weak Authentication