CVE-2020-26214

Improper Authentication in pypi/alerta-server

Identifier

CVE-2020-26214

Package Slug

pypi/alerta-server

Vulnerability

Improper Authentication

Description

In Alerta, users may be able to bypass LDAP authentication if they provide an empty password when Alerta server is configure to use LDAP as the authorization provider. Only deployments where LDAP servers are configured to allow unauthenticated authentication mechanism for anonymous authorization are affected. A fix has been implemented that returns HTTP Unauthorized response for any authentication attempts where the password field is empty. As a workaround LDAP administrators can disallow unauthenticated bind requests by clients.

Affected Versions

All versions before 7.5.7, all versions starting from 8.0.0 before 8.1.0

Solution

Upgrade to versions 7.5.7, 8.1.0 or above.

Last Modified

2020-11-18

source