Showing 1 vulnerability on this page for Yugabyte DB

Signals CISA KEV Ransomware Nuclei
YugaByte, Inc. vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

The software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active Directory

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

CWE-16CWE-287Aug 12, 2022
CVSS8.3v3.1EPSS0.868%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX