LDAP login with empty password
Reported by Alexei Bratuhin | 2011-11-15 08:21:17 UTC
If LDAP servers supports anonymous sessions, then a login with
an username (existing in LDAP) and empty password becomes
possible.
The problem is that call to InitialDirContext constructor doesn't
require an AD bind and if Context.SECURITY_CREDENTIALS contains
empty string authentication method 'none' (anonymous) is used.
Affected: Rundeck 1.3+ with implemented
http://rundeck.lighthouseapp.com/projects/59277-development/tickets...
See commit
https://github.com/coiouhkc/rundeck/commit/a8f999efc66d2131800fd53e...
Possible workaround is:
JettyCachingLdapLoginModule.java, ll.528-534
String pass = (String) password;
Hashtable environment = getEnvironment();
environment.put(Context.SECURITY_PRINCIPAL, userDn);
environment.put(Context.SECURITY_CREDENTIALS,
(pass.trim().isEmpty() ? "password_that_would_be never_used" :
pass));
DirContext dirContext = new InitialDirContext(environment);
No comments found
Create your profile
Help contribute to this project by taking a few moments to create your personal profile. Create your profile ยป
(DEPRECATED) Please use github issues for issue tracking at http://github.com/dtolabs/rundeck/issues
People watching this ticket
- Nobody is watching this ticket.