nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-37397 CVE-2022-37397
HIGH
The software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active Directory
Record summary
CVE-2022-37397 has a selected CVSS score of 8.3 (high).
Description
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Yugabyte DBBrowse YugaByte, Inc. / Yugabyte DB | CVE List | 2.6.1.0 | affected |
References
2yugabyte.comConfirmation
https://www.yugabyte.com/