CVE-2022-37397: The software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active Directory
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-37397?
CVE-2022-37397 is a vulnerability in YugabyteDB 2.6.1 that allows bypass of authentication when using LDAP-based authentication with Microsoft's Active Directory.
How does CVE-2022-37397 affect YugabyteDB?
CVE-2022-37397 affects YugabyteDB 2.6.1 when using LDAP-based authentication with Microsoft's Active Directory.
What is the severity of CVE-2022-37397?
CVE-2022-37397 has a severity rating of 9.8 (Critical).
How can I fix CVE-2022-37397?
To fix CVE-2022-37397, it is recommended to disable anonymous or unauthenticated LDAP binding or ensure that a strong password is set for LDAP authentication.
Where can I find more information about CVE-2022-37397?
More information about CVE-2022-37397 can be found at https://www.yugabyte.com/.