CVE-2022-37397
EUVD-2022-4003012.08.2022, 20:15
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| yugabyte | yugabytedb | 2.6.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration