VYPR
Unrated severityNVD Advisory· Published Aug 12, 2022· Updated Aug 3, 2024

The software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active Directory

CVE-2022-37397

Description

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.