VULNERABILITY INTELLIGENCE
CVE-2014-8763
CVSS score5 MEDIUM
EPSS probability2.52%
CISA KEVNot currently listed
Published2014-10-22
Last modified2026-06-17
CVSS vectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Description
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind.
Weakness classification
- CWE-287: Improper Authentication
Primary references
- secalert@redhat.com
- secalert@redhat.com
- secalert@redhat.com
- secalert@redhat.com
- secalert@redhat.com
- secalert@redhat.com
- secalert@redhat.com
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108