Learn about CVE-2022-37397 affecting Yugabyte DB 2.6.1.0 due to LDAP-based authentication vulnerability, allowing bypass with empty password. Find mitigation steps.
A detailed analysis of CVE-2022-37397, a vulnerability in the software Yugabyte DB when using LDAP-based authentication in YCQL with Microsoft’s Active Directory.