CVE-2014-4668: Cherokee-Project Cherokee

Medium severity, CVSS 6.8. EPSS: 2.8% chance of exploitation in the next 30 days.

The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.

Affected products

  • Cherokee-Project Cherokee: up to and including 1.2.103; version 1.2.2 only; version 1.2.98 only; version 1.2.99 only; version 1.2.101 only; version 1.2.102 only
  • Fedoraproject Fedora: version 20 only; version 21 only; version 22 only
  • Mageia Project Mageia: version 4 only

Published 2014-07-02. Last modified 2026-06-17.