First published: Sun Mar 22 2020(Updated: )
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MITRE CALDERA | <2.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10807 is an authentication bypass vulnerability in Caldera before version 2.6.5.
The authentication bypass occurs for REST API requests through a forged "localhost" string in the HTTP Host header.
The severity rating of CVE-2020-10807 is medium with a severity value of 5.3.
Caldera versions up to exclusive 2.6.5 are affected by CVE-2020-10807.
To fix the authentication bypass vulnerability, update Caldera to version 2.6.5 or higher.