An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the service integrated with which Active Directory is deployed at the level granted to the authenticating account.
References
Configurations
History
21 Nov 2024, 05:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://jira.percona.com/browse/PS-7358 - Issue Tracking, Permissions Required, Vendor Advisory | |
References | () https://jira.percona.com/browse/PSMDB-726 - Issue Tracking, Permissions Required, Vendor Advisory | |
References | () https://www.percona.com/blog/2020/10/13/percona-distribution-for-mysql-pxc-variant-8-0-20-fixes-for-security-vulnerability-release-roundup-october-13-2020/ - Release Notes, Vendor Advisory | |
References | () https://www.percona.com/doc/percona-distribution-mysql/8.0/release-notes-pxc-v8.0.20.upd2.html - Release Notes, Vendor Advisory |
Information
Published : 2020-11-09 20:15
Updated : 2024-11-21 05:20
NVD link : CVE-2020-26542
Mitre link : CVE-2020-26542
CVE.ORG link : CVE-2020-26542
JSON object : View
Products Affected
percona
- percona_server
CWE
CWE-287
Improper Authentication