Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0918 Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.
Github GHSA Github GHSA GHSA-3f8r-4qwm-r7jf Improper Authentication in Apache Traffic Control
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T23:17:40.016Z

Reserved: 2019-05-28T00:00:00

Link: CVE-2019-12405

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-09T17:15:13.033

Modified: 2024-11-21T04:22:46.363

Link: CVE-2019-12405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses