CVE-2012-4494

The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibly have other impacts by logging in.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:niif:shibb_auth:7.x-4.0:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:43

Type Values Removed Values Added
References () http://drupal.org/node/1493244 - () http://drupal.org/node/1493244 -
References () http://drupal.org/node/1719392 - Vendor Advisory () http://drupal.org/node/1719392 - Vendor Advisory
References () http://drupalcode.org/project/shib_auth.git/commitdiff/2032f0a - () http://drupalcode.org/project/shib_auth.git/commitdiff/2032f0a -
References () http://www.openwall.com/lists/oss-security/2012/10/04/6 - () http://www.openwall.com/lists/oss-security/2012/10/04/6 -
References () http://www.openwall.com/lists/oss-security/2012/10/07/1 - () http://www.openwall.com/lists/oss-security/2012/10/07/1 -

Information

Published : 2012-10-31 16:55

Updated : 2024-11-21 01:43


NVD link : CVE-2012-4494

Mitre link : CVE-2012-4494

CVE.ORG link : CVE-2012-4494


JSON object : View

Products Affected

drupal

  • drupal

niif

  • shibb_auth
CWE
CWE-264

Permissions, Privileges, and Access Controls