First published: Mon Sep 09 2019(Updated: )
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/apache/trafficcontrol | >=3.0.0<=3.0.1 | 3.0.2-RC1 |
Apache Traffic Control | =3.0.0 | |
Apache Traffic Control | =3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.