First published: Fri Aug 12 2022(Updated: )
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.
Credit: security@yugabyte.com
Affected Software | Affected Version | How to fix |
---|---|---|
YugabyteDB Managed | =2.6.1 |
Upgrade to non-vulnerable version 2.6.1.1+
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37397 is a vulnerability in YugabyteDB 2.6.1 that allows bypass of authentication when using LDAP-based authentication with Microsoft's Active Directory.
CVE-2022-37397 affects YugabyteDB 2.6.1 when using LDAP-based authentication with Microsoft's Active Directory.
CVE-2022-37397 has a severity rating of 9.8 (Critical).
To fix CVE-2022-37397, it is recommended to disable anonymous or unauthenticated LDAP binding or ensure that a strong password is set for LDAP authentication.
More information about CVE-2022-37397 can be found at https://www.yugabyte.com/.