Skip to content

When using LDAP, authentication process may be bypassed #4562

@TheWitness

Description

@TheWitness

Describe the bug

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

Expected behavior

Cacti security model should work when Anonymous binding is enabled.

Metadata

Metadata

Assignees

No one assigned

    Labels

    SECURITYA security issue reported through CVEbugUndesired behaviourresolvedA fixed issue

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions