CVE-2024-39848

Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.
Configurations

No configuration.

History

27 Mar 2025, 20:15

Type Values Removed Values Added
CWE CWE-1390

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://spaces.at.internet2.edu/display/Grouper/Grouper+bug+-+GRP-5515+-+web+services+LDAP+authentication+security+vulnerability - () https://spaces.at.internet2.edu/display/Grouper/Grouper+bug+-+GRP-5515+-+web+services+LDAP+authentication+security+vulnerability -

03 Jul 2024, 02:05

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-29 22:15

Updated : 2025-03-27 20:15


NVD link : CVE-2024-39848

Mitre link : CVE-2024-39848

CVE.ORG link : CVE-2024-39848


JSON object : View

Products Affected

No product.

CWE
CWE-1390

Weak Authentication