CVE-2014-8088Improper Authentication in Framework

Severity
5.0MEDIUMNVD
EPSS
0.6%
top 30.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22
Latest updateMay 17

Description

The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Packagistzendframework/zendframework2.0.02.0.99+3
Packagistzendframework/zendframework11.12.01.12.9
NVDzend/zend_framework1.12.7+16

🔴Vulnerability Details

4
GHSA
Zend Access Restriction Bypass2022-05-17
OSV
Zend Access Restriction Bypass2022-05-17
OSV
CVE-2014-8088: The (1) Zend_Ldap class in Zend before 12014-10-22
CVEList
CVE-2014-8088: The (1) Zend_Ldap class in Zend before 12014-10-22

💬Community

1
Bugzilla
CVE-2014-8088 php-ZendFramework: null byte issue, connect to LDAP without knowing the password (ZF2014-05)2014-10-10
CVE-2014-8088 — Improper Authentication in Framework | cvebase