Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-desktop" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-dev" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-help-de" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-help-en" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-help-fr" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-help-nl" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-connectivity" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-dhcp" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-dhcp-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-dns" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-dns-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-fai" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-fai-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-gofax" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-gofon" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-goto" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-kolab" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-kolab-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-ldapmanager" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-mail" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-mit-krb5" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-mit-krb5-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-nagios" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-nagios-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-netatalk" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-opengroupware" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-openxchange" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-openxchange-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-opsi" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-phpgw" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-phpgw-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-phpscheduleit" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-phpscheduleit-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-pptp" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-pptp-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-pureftpd" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-pureftpd-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-rolemanagement" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-rsyslog" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-samba" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-scalix" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-squid" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-ssh" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-ssh-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-sudo" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-sudo-schema" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-systems" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-uw-imap" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-plugin-webdav" }, { "binary_version": "2.7.4+reloaded2-9ubuntu1.1", "binary_name": "gosa-schema" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-alias" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-alias-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-applications" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-applications-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-argonaut" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-argonaut-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-audit" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-audit-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-autofs" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-autofs-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-certificates" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-community" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-community-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-cyrus" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-cyrus-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-debconf" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-debconf-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-developers" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-dhcp" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-dhcp-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-dns" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-dns-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-dovecot" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-dovecot-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-dsa" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-dsa-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ejbca" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ejbca-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-fai" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-fai-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-freeradius" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-freeradius-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-fusioninventory" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-fusioninventory-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-gpg" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-gpg-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ipmi" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ipmi-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ldapdump" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ldapmanager" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-mail" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-mail-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-mixedgroups" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-nagios" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-nagios-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-netgroups" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-netgroups-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-newsletter" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-newsletter-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-opsi" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-opsi-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-personal" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-personal-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-posix" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-postfix" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-postfix-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ppolicy" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ppolicy-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-puppet" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-puppet-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-pureftpd" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-pureftpd-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-quota" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-quota-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-renater-partage" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-renater-partage-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-repository" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-repository-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-samba" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-samba-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-sogo" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-sogo-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-spamassassin" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-spamassassin-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-squid" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-squid-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ssh" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-ssh-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-subcontracting" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-subcontracting-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-sudo" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-sudo-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-supann" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-supann-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-sympa" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-sympa-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-systems" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-systems-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-user-reminder" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-user-reminder-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-weblink" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-weblink-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-webservice" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-plugin-webservice-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-schema" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-smarty3-acl-render" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-theme-oxygen" }, { "binary_version": "1.2.3-5", "binary_name": "fusiondirectory-webservice-shell" } ] }