CVE-2014-8764Improper Authentication in Dokuwiki

Severity
5.0MEDIUMNVD
EPSS
1.2%
top 20.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22
Latest updateMay 17

Description

DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Debiandokuwiki/dokuwiki< 0.0.20140929.a-1+3
NVDdokuwiki/dokuwiki2013-12-08
NVDmageia_project/mageia3.0, 4.0+1

🔴Vulnerability Details

3
GHSA
GHSA-5pq8-pcjm-mv95: DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user nam2022-05-17
OSV
CVE-2014-8764: DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user nam2014-10-22
CVEList
CVE-2014-8764: DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user nam2014-10-22

📋Vendor Advisories

1
Debian
CVE-2014-8764: dokuwiki - DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentic...2014

💬Community

1
Bugzilla
CVE-2014-8761 CVE-2014-8762 CVE-2014-8763 CVE-2014-8764 dokuwiki: various security flaws2014-10-07
CVE-2014-8764 — Improper Authentication in Dokuwiki | cvebase