CVE Published: 20/11/2024 |
CVE Updated: 21/11/2024 |
CVE Year: 2024 Source: M-Files Corporation |
Vendor: M-Files Corporation |
Product: M-Files Server Status : PUBLISHED
CVE-2024-10127 Description
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.