CVE-2014-8764 — Improper Authentication in Dokuwiki
Severity
5.0MEDIUMNVD
EPSS
1.2%
top 20.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 22
Latest updateMay 17
Description
DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind.
CVSS vector
AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
3GHSA▶
GHSA-5pq8-pcjm-mv95: DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user nam↗2022-05-17
OSV▶
CVE-2014-8764: DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user nam↗2014-10-22
CVEList▶
CVE-2014-8764: DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user nam↗2014-10-22
📋Vendor Advisories
1Debian▶
CVE-2014-8764: dokuwiki - DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentic...↗2014
💬Community
1Bugzilla
▶