Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
The software is vulnerable when using LDAP-based authentication in YCQL with Microsoft’s Active Directory
Vulnerability Description
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
认证机制不恰当
Vulnerability Title
YugabyteDB 授权问题漏洞
Vulnerability Description
YugabyteDB是美国Yugabyte公司的一款用于云原生应用程序的高性能事务性分布式 SQL 数据库。 YugabyteDB 2.6.1版本存在安全漏洞,该漏洞源于当启用匿名或未经身份验证的 LDAP 绑定时,允许使用空密码绕过身份验证。
CVSS Information
N/A
Vulnerability Type
N/A