CVE-2024-36070 Information
May 20, 2024
cve
Description
tine before 2023.11.8 when an LDAP backend is used allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is also available for the 2022.11 series.)
Reference
https://github.com/tine-groupware/tine/releases/tag/2023.11.8 https://github.com/tine-groupware/tine/commit/5d556a1225aa358cbf7cfbeae518c9386b46f516
Share on: