First published: Wed Nov 20 2024(Updated: )
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
Credit: security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-Files | <24.11 |
Update to patched version
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10127 has a high severity rating due to its potential to allow unauthorized access through authentication bypass.
To fix CVE-2024-10127, upgrade M-Files Server to version 24.11 or later and ensure the LDAP server is configured securely.
CVE-2024-10127 affects all versions of M-Files Server prior to version 24.11.
Yes, CVE-2024-10127 specifically involves vulnerability in OpenLDAP configurations that allow authentication without a password.
Mitigation without upgrading is not recommended, but securing your LDAP server configuration can reduce risk while planning an upgrade.