tine before 2023.11.8, when an LDAP backend is used,...
High severity
Unreviewed
Published
May 19, 2024
to the GitHub Advisory Database
•
Updated Mar 27, 2025
Description
Published by the National Vulnerability Database
May 19, 2024
Published to the GitHub Advisory Database
May 19, 2024
Last updated
Mar 27, 2025
tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is also available for the 2022.11 series.)
References