CVE-2012-4494

The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibly have other impacts by logging in.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:niif:shibb_auth:7.x-4.0:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-10-31 16:55

Updated : 2024-02-28 12:00


NVD link : CVE-2012-4494

Mitre link : CVE-2012-4494

CVE.ORG link : CVE-2012-4494


JSON object : View

Products Affected

niif

  • shibb_auth

drupal

  • drupal
CWE
CWE-264

Permissions, Privileges, and Access Controls