Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-26214 PoC — Alerta 授权问题漏洞

Source
Associated Vulnerability
Title:Alerta 授权问题漏洞 (CVE-2020-26214)
Description:Alerta是个人开发者的一个 Python 编写的监控系统。 Alerta 8.1.0 之前版本存在授权问题漏洞,该漏洞源于用户在将Alerta服务器配置为使用LDAP作为授权提供程序时提供一个空密码,那么他们就可以绕过LDAP身份验证。
Description
Alerta prior to version 8.1.0 is prone to authentication bypass when using LDAP as an authorization provider and the LDAP server accepts Unauthenticated Bind requests.
File Snapshot

id: CVE-2020-26214 info: name: Alerta < 8.1.0 - Authentication Bypass author: CasperGN,daffainf ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.