go-ldap Project ldap 2.5.0

CPE Details

go-ldap Project ldap 2.5.0
2.5.0
2017-10-05
13h45 +00:00
2021-06-02
15h31 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:go-ldap_project:ldap:2.5.0:*:*:*:*:*:*:*

Informations

Vendor

go-ldap_project

Product

ldap

Version

2.5.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2017-14623 2017-09-20 23h00 +00:00 In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application using this package if these conditions are met: (1) it relies only on the return error of the Bind function call to determine whether a user is authorized (i.e., a nil return value is interpreted as successful authorization) and (2) it is used with an LDAP server allowing unauthenticated bind.
8.1
Haute