Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2020-26214— LDAP authentication bypass in Alerta

Quick assessment

Affected
alerta alerta
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Alerta是个人开发者的一个 Python 编写的监控系统。 Alerta 8.1.0 之前版本存在授权问题漏洞,该漏洞源于用户在将Alerta服务器配置为使用LDAP作为授权提供程序时提供一个空密码,那么他们就可以绕过LDAP身份验证。

CVSS 9.1 · Critical EPSS 65.93% · P99

Public Exploits 1

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-26214

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LDAP authentication bypass in Alerta
Source: CVE Program / CVE List V5
Vulnerability Description
In Alerta before version 8.1.0, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deployments where LDAP servers are configured to allow unauthenticated authentication mechanism for anonymous authorization are affected. A fix has been implemented in version 8.1.0 that returns HTTP 401 Unauthorized response for any authentication attempts where the password field is empty. As a workaround LDAP administrators can disallow unauthenticated bind requests by clients.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Alerta 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Alerta是个人开发者的一个 Python 编写的监控系统。 Alerta 8.1.0 之前版本存在授权问题漏洞,该漏洞源于用户在将Alerta服务器配置为使用LDAP作为授权提供程序时提供一个空密码,那么他们就可以绕过LDAP身份验证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
alerta alerta < 8.1.0 -

II. Public POCs for CVE-2020-26214

# POC Description Source Link Shenlong Link
1 Alerta prior to version 8.1.0 is prone to authentication bypass when using LDAP as an authorization provider and the LDAP server accepts Unauthenticated Bind requests. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26214.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-26214

登录查看更多情报信息。

Patches & Fixes for CVE-2020-26214 (2)

Vendor Advisories for CVE-2020-26214 (1)

Other References for CVE-2020-26214 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2020-26214

No comments yet


Leave a comment