CVE-2014-8763Improper Authentication in Dokuwiki

Severity
5.0MEDIUMNVD
EPSS
1.1%
top 22.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22
Latest updateMay 17

Description

DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Debiandokuwiki/dokuwiki< 0.0.20140929.a-1+3
NVDdokuwiki/dokuwiki2014-05-05a
NVDmageia_project/mageia3.0, 4.0+1

🔴Vulnerability Details

3
GHSA
GHSA-w8gh-9jqp-v528: DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password star2022-05-17
OSV
CVE-2014-8763: DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password star2014-10-22
CVEList
CVE-2014-8763: DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password star2014-10-22

📋Vendor Advisories

1
Debian
CVE-2014-8763: dokuwiki - DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication...2014

💬Community

1
Bugzilla
CVE-2014-8761 CVE-2014-8762 CVE-2014-8763 CVE-2014-8764 dokuwiki: various security flaws2014-10-07
CVE-2014-8763 — Improper Authentication in Dokuwiki | cvebase