2 results (0.003 seconds)

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

29 Jun 2024 — Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1. Internet2 Grouper anterior a 5.6 permite omitir la autenticación cuando la autenticación LDAP se utiliza de ciertas maneras. Esto está relacionado con internet2.middleware.grouper.ws.security.WsGro... • https://spaces.at.internet2.edu/display/Grouper/Grouper+bug+-+GRP-5515+-+web+services+LDAP+authentication+security+vulnerability • CWE-1390: Weak Authentication •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 2

03 Dec 2018 — Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary web script or HTML via the code parameter. Vulnerabilidad Cross-Site Scripting (XSS) en UiV2Public.index en Internet2 Grouper 2.2 y 2.3 permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante el parámetro code. • https://bugs.internet2.edu/jira/browse/GRP-1838 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •