The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote attackers to bypass authentication via unspecified vectors.
https://github.com/advisories/GHSA-9whh-582r-589h
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3457