Improper Authentication in Apache Traffic Control
Critical severity
GitHub Reviewed
Published
May 18, 2021
to the GitHub Advisory Database
•
Updated Sep 18, 2023
Package
Affected versions
>= 3.0.0, <= 3.0.1
Patched versions
3.0.2-RC1
Description
Published by the National Vulnerability Database
Sep 9, 2019
Reviewed
May 17, 2021
Published to the GitHub Advisory Database
May 18, 2021
Last updated
Sep 18, 2023
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.
References