CVE-2014-0132
The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.
- Affected products
- 389-Ds-Base, Centos, Red Hat
- Fedoraproject 389 Directory Server
- ≤ 1.2.11.25, 1.2.11.1, 1.2.11.5, 1.2.11.6, 1.2.11.8, 1.2.11.9, 1.2.11.10, 1.2.11.11, 1.2.11.12, 1.2.11.13, 1.2.11.14, 1.2.11.15, 1.2.11.17, 1.2.11.19, 1.2.11.20, 1.2.11.21, 1.2.11.22, 1.2.11.23
- Fix
- Available
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2014-03-18
CVE-2014-0132 at NVD
1 known exploit for CVE-2014-0132
Proof-of-concept code and exploit modules indexed by Sploitus