CVE-2014-3999

HIGH

Horde_Ldap < 2.0.6 - Authentication Bypass via LDAP Bind User DN

Title source: llm
STIX 2.1

Description

The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/06/14/1
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1109628
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68014
Mailing List mailing-list x_refsource_mlist
https://marc.info/?l=horde-announce&m=140178644816474&w=2

Scores

CVSS v3 8.1
EPSS 0.0255
EPSS Percentile 83.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
horde/horde_ldap < 2.0.6
Published Apr 10, 2018
Tracked Since Feb 18, 2026