Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.
History

Tue, 25 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Internet2
Internet2 grouper
CPEs cpe:2.3:a:internet2:grouper:5.6:*:*:*:*:*:*:*
Vendors & Products Internet2
Internet2 grouper
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-06-29T00:00:00.000Z

Updated: 2025-03-25T16:11:17.278Z

Reserved: 2024-06-29T00:00:00.000Z

Link: CVE-2024-39848

cve-icon Vulnrichment

Updated: 2024-08-02T04:33:10.226Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-29T22:15:02.263

Modified: 2024-11-21T09:28:26.230

Link: CVE-2024-39848

cve-icon Redhat

No data.