• 公告ID (KylinSec-SA-2023-1580)

摘要:

An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system does not require the password to be (re)entered. This results in exposing cleartext credentials when connecting to a rogue LDAP server.

安全等级: Low

公告ID: KylinSec-SA-2023-1580

发布日期: 2023年8月1日

关联CVE: CVE-2023-35833  

  • 详细介绍

1. 漏洞描述

   

An issue was discovered in YSoft SAFEQ 6 Server before 6.0.82. When modifying the URL of the LDAP server configuration from LDAPS to LDAP, the system does not require the password to be (re)entered. This results in exposing cleartext credentials when connecting to a rogue LDAP server.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-35833 KY3.4-4A python-ldap Unaffected
CVE-2023-35833 KY3.4-5 python-ldap Unaffected
CVE-2023-35833 KY3.5.1 python-ldap Unaffected
CVE-2023-35833 KY3.5.2 python-ldap Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2023-1579 下一篇:KylinSec-SA-2023-1581