CVE-2014-7807
Apache CloudStack 4.3 / 4.4 Unauthenticated LDAP Binds
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
Apache CloudStack 4.3.x anterior a 4.3.2 y 4.4.x anterior a 4.4.2 permite a atacantes remotos evadir la autenticación a través de una solicitud de inicio de sesión sin contraseña, lo que provoca un vínculo no autenticado.
Apache CloudStack may be configured to authenticate LDAP users. When so configured, it performs a simple LDAP bind with the name and password provided by a user. Simple LDAP binds are defined with three mechanisms (RFC 4513): 1) username and password; 2) unauthenticated if only a username is specified; and 3) anonymous if neither username or password is specified. Currently, Apache CloudStack does not check if the password was provided which could allow an attacker to bind as an unauthenticated user. Versions 4.3 and 4.4 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-10-03 CVE Reserved
- 2014-12-09 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://support.citrix.com/article/CTX200285 | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/534176/100/0/threaded | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Cloudstack Search vendor "Apache" for product "Cloudstack" | 4.3.0 Search vendor "Apache" for product "Cloudstack" and version "4.3.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cloudstack Search vendor "Apache" for product "Cloudstack" | 4.3.1 Search vendor "Apache" for product "Cloudstack" and version "4.3.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cloudstack Search vendor "Apache" for product "Cloudstack" | 4.4.0 Search vendor "Apache" for product "Cloudstack" and version "4.4.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Cloudstack Search vendor "Apache" for product "Cloudstack" | 4.4.1 Search vendor "Apache" for product "Cloudstack" and version "4.4.1" | - |
Affected
|