Record summary

CVE-2022-37397 has a selected CVSS score of 8.3 (high).

Description

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.6.1.0affected

References

2