Description
On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
No analysis available yet.
Remediation
Vendor Solution
Lider component should be updated to 2.1.16.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-27074 | On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials. |
References
History
Mon, 18 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 16 Sep 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials. | On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials. |
Status: PUBLISHED
Assigner: TR-CERT
Published:
Updated: 2026-05-18T08:11:21.125Z
Reserved: 2021-09-22T00:00:00.000Z
Link: CVE-2021-3825
No data.
Status : Modified
Published: 2021-10-01T15:15:07.883
Modified: 2026-05-18T09:16:22.340
Link: CVE-2021-3825
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD