PT-2024-8764 · M Files · M-Files Server
Published
2024-11-20
·
Updated
2026-02-23
·
CVE-2024-10127
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
M-Files Server versions prior to 24.11
Description:
The issue is related to weaknesses in the authentication procedure of the M-Files Server platform, which can be exploited by a remote attacker to bypass authentication and elevate privileges. This is specifically related to the use of OpenLDAP configurations that allow user authentication without a password when the LDAP server itself has a vulnerable configuration.
Recommendations:
For M-Files Server versions prior to 24.11, update to version 24.11 or later to resolve the authentication bypass condition in LDAP authentication.
As a temporary workaround, consider disabling the use of OpenLDAP configurations that support anonymous binding until a patch is available.
Restrict access to the LDAP authentication module to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
M-Files Server