CVE-2020-26214
LDAP authentication bypass with empty password
9.1
CRITICAL
CVSS 3.1
EPSS 65.9%
描述
In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deployments where LDAP servers are configured to allow unauthenticated authentication mechanism for anonymous authorization are affected. A fix has been implemented in version 8.1.0 that returns HTTP 401 Unauthorized response for any authentication attempts where the password field is empty. As a workaround LDAP administrators can disallow unauthenticated bind requests by clients.
如何修補 CVE-2020-26214
要修補 CVE-2020-26214,請將受影響套件升級到下列已修補版本。
- —升級至 8.1.0 或更新版本
CVE-2020-26214 正在被利用嗎?
可能 — EPSS 為 65.9%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 8.0.0, < 8.1.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |