Alerta Authentication Bypass

By
Febna V M
Published on
16 Jun 2021
Vulnerability

CVE-2020-26214 is a vulnerability in the Alerta server caused by improper authentication. CVE-2020-26214 is a flaw in the Alerta server caused by incorrect authentication. Users may be able to bypass LDAP authentication in Alerta prior to version 8.1.0 by using an empty password if the server is configured to use LDAP as the authorization provider. Only deployments with LDAP servers configured to enable anonymous authentication with no authentication are qualified. Only LDAP servers designed to allow anonymous authorization through unauthenticated authentication are affected. For any authentication attempts where the password field is empty, a patch has been introduced in version 8.1.0 that returns an HTTP 401 unauthorized response.

Mitigation / Precaution

We suggest that you update to version 8.1.0 in order to fix this vulnerability.

Automated human-like penetration testing for your web apps & APIs
Teams using Beagle Security are set up in minutes, embrace release-based CI/CD security testing and save up to 65% with timely remediation of vulnerabilities. Sign up for a free account to see what it can do for you.

Written by
Febna V M
Febna V M
Cyber Security Engineer
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days
Find surface-level website security issues in under a minute
Free website security assessment
Experience the power of automated penetration testing & contextual reporting.