{"id":"GHSA-9whh-582r-589h","summary":"ldap_fluff authentication bypass","details":"The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote attackers to bypass authentication via unspecified vectors.","aliases":["CVE-2012-5604"],"modified":"2024-12-05T05:43:18.873316Z","published":"2022-05-14T03:24:09Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-01-26T23:52:39Z","nvd_published_at":"2013-03-01T05:40:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5604"},{"type":"WEB","url":"https://github.com/theforeman/ldap_fluff/commit/e4c90a522275aeaa48ca9982ce75597f0954af48"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=882136"},{"type":"PACKAGE","url":"https://github.com/theforeman/ldap_fluff"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2013-0544.html"}],"affected":[{"package":{"name":"ldap_fluff","ecosystem":"RubyGems","purl":"pkg:gem/ldap_fluff"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.0"}]}],"versions":["0.1.1","0.1.2","0.1.3","0.1.4","0.1.7","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.6","0.3.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9whh-582r-589h/GHSA-9whh-582r-589h.json"}}],"schema_version":"1.9.0"}