ZeroHour

CVE-2022-37397

CVSS 3.1
9.8 critical
EPSS
<1%p57
Published
()
Modified
Description

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

Vendors
yugabyte
Products
yugabytedb
Weakness
CWE-16, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.