Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNmOHItNHF3bS1yN2pm

Improper Authentication in Apache Traffic Control

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.

Permalink: https://github.com/advisories/GHSA-3f8r-4qwm-r7jf
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTNmOHItNHF3bS1yN2pm
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: almost 3 years ago
Updated: 8 months ago


CVSS Score: 9.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-3f8r-4qwm-r7jf, CVE-2019-12405
References: Repository: https://github.com/apache/trafficcontrol
Blast Radius: 3.0

Affected Packages

go:github.com/apache/trafficcontrol
Dependent packages: 1
Dependent repositories: 2
Downloads:
Affected Version Ranges: >= 3.0.0, <= 3.0.1
Fixed in: 3.0.2-RC1
All affected versions:
All unaffected versions: 1.1.3, 5.0.0, 5.1.0, 5.1.1, 5.1.2, 5.1.3, 5.1.4, 5.1.6, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 7.0.0, 7.0.1