GHSA-3f8r-4qwm-r7jf

Suggest an improvement
Source
https://github.com/advisories/GHSA-3f8r-4qwm-r7jf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-3f8r-4qwm-r7jf/GHSA-3f8r-4qwm-r7jf.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-3f8r-4qwm-r7jf
Aliases
Published
2021-05-18T15:39:16Z
Modified
2023-11-01T04:50:19.496298Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Improper Authentication in Apache Traffic Control
Details

Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.

Database specific
{
    "nvd_published_at": "2019-09-09T17:15:00Z",
    "cwe_ids": [
        "CWE-287"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2021-05-17T21:00:28Z"
}
References

Affected packages

Go / github.com/apache/trafficcontrol

Package

Name
github.com/apache/trafficcontrol
View open source insights on deps.dev
Purl
pkg:golang/github.com/apache/trafficcontrol

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.0.2-RC1

Database specific

{
    "last_known_affected_version_range": "<= 3.0.1"
}