Security Advisory

CVE-2024-36070

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-05-19 18:48:57
Last updated 2025-03-27 19:09:08
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is also available for the 2022.11 series.)