CRITICAL9.8
GHSA-3f8r-4qwm-r7jf
Improper Authentication in Apache Traffic Control
Quick fix
GHSA-3f8r-4qwm-r7jf — github.com/apache/trafficcontrol: upgrade to the fixed version with the command below.
go get github.com/apache/trafficcontrol@v3.0.2-RC1Details
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/apache/trafficcontrol
Introduced in:
3.0.0Fixed in: 3.0.2-RC1Fix
go get github.com/apache/trafficcontrol@v3.0.2-RC1References
- https://nvd.nist.gov/vuln/detail/CVE-2019-12405[ADVISORY]
- https://github.com/apache/trafficcontrol/commit/f780aff77a52d52a37b4d1cc3e8e801c0b557356[WEB]
- https://github.com/apache/trafficcontrol[PACKAGE]
- https://lists.apache.org/thread.html/e128e9d382f3b0d074e2b597ac58e1d92139394509d81ddbc9e3700e@%3Cusers.trafficcontrol.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/r3c675031ac220b5eae64a9c84a03ee60045c6045738607dca4a96cb8@%3Ccommits.trafficcontrol.apache.org%3E[WEB]
- https://lists.apache.org/thread.html/rc8bfd7d4f71d61e9193efcd4699eccbab3c202ec1d75ed9d502f08bf@%3Ccommits.trafficcontrol.apache.org%3E[WEB]
- https://support.f5.com/csp/article/K84141859[WEB]
- https://support.f5.com/csp/article/K84141859?utm_source=f5support&utm_medium=RSS[WEB]