CVE-2022-43959: Infoleak
Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remote administrators to discover an AD/LDAP administrative password by reading the source code of /bitrix/admin/ldapserveredit.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43959?
The severity of CVE-2022-43959 is medium with a CVSS score of 4.9.
How can remote administrators discover the AD/LDAP administrative password in CVE-2022-43959?
Remote administrators can discover the AD/LDAP administrative password by reading the source code of /bitrix/admin/ldap_server_edit.php in 1C-Bitrix Bitrix24 version up to 22.200.200.
How can I fix CVE-2022-43959?
To fix CVE-2022-43959, upgrade to a version of 1C-Bitrix Bitrix24 equal to or above 22.200.200.
Where can I find more information about CVE-2022-43959?
For more information about CVE-2022-43959, you can visit the following references: [GitHub](https://github.com/secware-ru/CVE-2022-43959), [Bitrix24 Pricing](https://www.bitrix24.com/prices/self-hosted.php), [Bitrix24 Security](https://www.bitrix24.com/security/).