On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-27074 | On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials. |
Fixes
Solution
Lider component should be updated to 2.1.16.
Workaround
No workaround given by the vendor.
References
History
Mon, 16 Sep 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials. | On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials. |
Status: PUBLISHED
Assigner: TR-CERT
Published:
Updated: 2024-09-16T19:56:05.415Z
Reserved: 2021-09-22T00:00:00
Link: CVE-2021-3825
No data.
Status : Modified
Published: 2021-10-01T15:15:07.883
Modified: 2024-11-21T06:22:32.840
Link: CVE-2021-3825
No data.
OpenCVE Enrichment
No data.
EUVD