Comment 17 for bug 1187305

Revision history for this message
Thierry Carrez (ttx) wrote : Re: LDAP vulnerability when checking user credentials

Jose: just to make sure we cover your case... You don't do anonymous binding but you use an account with an empty password, then ? (ldap.password not set). If both ldap.user and ldap.password are set, then from our current analysis the bind with empty password should fail.