Sploitus

CVE-2022-37397

No indexed exploits for CVE-2022-37397 yet

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

Affected products
Active Directory, Yugabytedb
Yugabyte Yugabytedb
= 2.6.1
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
0.8% (52th percentile)
Weakness
CWE-287, CWE-16
NVD status
Modified
Published
2022-08-12

Fix

Upgrade to non-vulnerable version 2.6.1.1+

Workaround

Disable LDAP for YCQL.

CVE-2022-37397 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-37397 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-37397 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.