CVE-2019-12405

CRITICAL

Apache Traffic Control <3.0.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.

Scores

CVSS v3 9.8
EPSS 0.0117
EPSS Percentile 78.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (3)
apache/traffic_control 3.0.0
apache/traffic_control 3.0.1
apache/trafficcontrol 3.0.0 - 3.0.2-RC1Go
Published Sep 09, 2019
Tracked Since Feb 18, 2026