Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Internet2
Internet2 grouper |
|
CPEs | cpe:2.3:a:internet2:grouper:5.6:*:*:*:*:*:*:* | |
Vendors & Products |
Internet2
Internet2 grouper |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-06-29T00:00:00.000Z
Updated: 2025-03-25T16:11:17.278Z
Reserved: 2024-06-29T00:00:00.000Z
Link: CVE-2024-39848

Updated: 2024-08-02T04:33:10.226Z

Status : Awaiting Analysis
Published: 2024-06-29T22:15:02.263
Modified: 2024-11-21T09:28:26.230
Link: CVE-2024-39848

No data.