PT-2024-4057 · Tripwire · Tripwire Enterprise
Published
2024-06-03
·
Updated
2025-08-29
·
CVE-2024-4332
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/S:N/AU:Y/R:U/V:C/RE:L/U:Red |
Name of the Vulnerable Software and Affected Versions:
Tripwire Enterprise version 9.1.0
Description:
An authentication bypass issue has been identified in the REST and SOAP API components of Tripwire Enterprise when configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is enabled. This allows unauthenticated attackers to bypass authentication if a valid username is known, potentially leading to remote attackers gaining privileged access to the APIs and resulting in unauthorized information disclosure or modification.
Recommendations:
For Tripwire Enterprise version 9.1.0, consider disabling the "Auto-synchronize LDAP Users, Roles, and Groups" feature until a patch is available to prevent exploitation of the authentication bypass vulnerability. Additionally, restrict access to the REST and SOAP API components to minimize the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tripwire Enterprise