CVE-2015-5246

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:theforeman:foreman:1.9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:32

Type Values Removed Values Added
References () http://projects.theforeman.org/issues/11471 - Issue Tracking, Patch, Vendor Advisory () http://projects.theforeman.org/issues/11471 - Issue Tracking, Patch, Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=1258700 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=1258700 - Issue Tracking

Information

Published : 2017-10-06 15:29

Updated : 2024-11-21 02:32


NVD link : CVE-2015-5246

Mitre link : CVE-2015-5246

CVE.ORG link : CVE-2015-5246


JSON object : View

Products Affected

theforeman

  • foreman
CWE
CWE-254

7PK - Security Features