PT-2024-4057 · Tripwire · Tripwire Enterprise

Published

2024-06-03

·

Updated

2025-08-29

·

CVE-2024-4332

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/S:N/AU:Y/R:U/V:C/RE:L/U:Red
Name of the Vulnerable Software and Affected Versions: Tripwire Enterprise version 9.1.0
Description: An authentication bypass issue has been identified in the REST and SOAP API components of Tripwire Enterprise when configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is enabled. This allows unauthenticated attackers to bypass authentication if a valid username is known, potentially leading to remote attackers gaining privileged access to the APIs and resulting in unauthorized information disclosure or modification.
Recommendations: For Tripwire Enterprise version 9.1.0, consider disabling the "Auto-synchronize LDAP Users, Roles, and Groups" feature until a patch is available to prevent exploitation of the authentication bypass vulnerability. Additionally, restrict access to the REST and SOAP API components to minimize the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04502
CVE-2024-4332

Affected Products

Tripwire Enterprise