An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.yugabyte.com/ | Vendor Advisory | 
| https://www.yugabyte.com/ | Vendor Advisory | 
Configurations
                    History
                    21 Nov 2024, 07:14
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 8.3  | 
| References | () https://www.yugabyte.com/ - Vendor Advisory | 
Information
                Published : 2022-08-12 20:15
Updated : 2024-11-21 07:14
NVD link : CVE-2022-37397
Mitre link : CVE-2022-37397
CVE.ORG link : CVE-2022-37397
JSON object : View
Products Affected
                yugabyte
- yugabytedb
 
