Alerta是个人开发者的一个 Python 编写的监控系统。 Alerta 8.1.0 之前版本存在授权问题漏洞,该漏洞源于用户在将Alerta服务器配置为使用LDAP作为授权提供程序时提供一个空密码,那么他们就可以绕过LDAP身份验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Alerta prior to version 8.1.0 is prone to authentication bypass when using LDAP as an authorization provider and the LDAP server accepts Unauthenticated Bind requests. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26214.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet