Safety vulnerability ID: 26023
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Products.ldapuserfolder version 2.20 includes a fix for CVE-2010-2944: The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges.
https://github.com/dataflake/Products.LDAPUserFolder/commit/246257dbe5f73a6fd3c3e597814038977004cdd7
Latest version: 2.27
A LDAP-enabled Zope 2 user folder
The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application