CVE-2024-10127: Support for authentication bypass condition in M-Files LDAP authentication
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10127?
CVE-2024-10127 has a high severity rating due to its potential to allow unauthorized access through authentication bypass.
How do I fix CVE-2024-10127?
To fix CVE-2024-10127, upgrade M-Files Server to version 24.11 or later and ensure the LDAP server is configured securely.
Which versions of M-Files Server are affected by CVE-2024-10127?
CVE-2024-10127 affects all versions of M-Files Server prior to version 24.11.
Is CVE-2024-10127 related to OpenLDAP configurations?
Yes, CVE-2024-10127 specifically involves vulnerability in OpenLDAP configurations that allow authentication without a password.
Can I mitigate CVE-2024-10127 without upgrading my software?
Mitigation without upgrading is not recommended, but securing your LDAP server configuration can reduce risk while planning an upgrade.