CVE-2014-8088

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
22/10/2014
Last modified:
12/04/2025

Description

The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zend:zend_framework:*:*:*:*:*:*:*:* 1.12.7 (including)
cpe:2.3:a:zend:zend_framework:1.12.0:*:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:1.12.0:rc1:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:1.12.0:rc2:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:1.12.0:rc3:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:1.12.0:rc4:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:1.12.1:*:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:1.12.2:*:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:1.12.3:*:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:1.12.5:*:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:2.01:*:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:zend:zend_framework:2.2.4:*:*:*:*:*:*:*