CVE-2020-10807: Medium severity MITRE CALDERA vulnerability
Published Mar 22, 2020
·Updated
authsvc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.
Affected Software
1 affected component
MITRE CALDERA<2.6.5
Remediation
Patch Available
Event History
Mar 22, 2020
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
Description
Frequently Asked Questions
1
What is the vulnerability CVE-2020-10807?
CVE-2020-10807 is an authentication bypass vulnerability in Caldera before version 2.6.5.
2
How does the authentication bypass occur in Caldera?
The authentication bypass occurs for REST API requests through a forged "localhost" string in the HTTP Host header.
3
What is the severity of CVE-2020-10807?
The severity rating of CVE-2020-10807 is medium with a severity value of 5.3.
4
Which software versions are affected by CVE-2020-10807?
Caldera versions up to exclusive 2.6.5 are affected by CVE-2020-10807.
5
How can I fix the authentication bypass vulnerability in Caldera?
To fix the authentication bypass vulnerability, update Caldera to version 2.6.5 or higher.