The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote attackers to bypass authentication via unspecified vectors.
- https://bugzilla.redhat.com/show_bug.cgi?id=882136
No PoCs found on GitHub currently.