CVE-2022-37397

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
12/08/2022
Last modified:
16/08/2022

Description

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yugabyte:yugabytedb:2.6.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools