CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and accessing the Admin UI directly using the default user identity.(https://github.com/crate/crate/issues/15231)
References
Link | Resource |
---|---|
https://github.com/crate/crate/issues/15231 | Exploit Issue Tracking |
Configurations
History
No history.
Information
Published : 2024-01-30 01:15
Updated : 2024-02-06 18:30
NVD link : CVE-2023-51982
Mitre link : CVE-2023-51982
CVE.ORG link : CVE-2023-51982
JSON object : View
Products Affected
cratedb
- cratedb
CWE
CWE-287
Improper Authentication