PT-2020-16344 · Alerta · Alerta
Published
2020-11-06
·
Updated
2020-11-17
·
CVE-2020-26214
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Alerta versions prior to 8.1.0
Description
The issue allows users to bypass LDAP authentication by providing an empty password when the Alerta server is configured to use LDAP as the authorization provider. This affects deployments where LDAP servers are configured to allow unauthenticated authentication mechanisms for anonymous authorization. A fix has been implemented that returns an HTTP 401 Unauthorized response for any authentication attempts where the password field is empty.
Recommendations
For versions prior to 8.1.0, update to version 8.1.0 to resolve the issue.
As a temporary workaround, LDAP administrators can disallow unauthenticated bind requests by clients.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alerta