Back

CRITICAL

Support for authentication bypass condition in M-Files LDAP authentication

Published Nov 20, 2024

Description

Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.

Affected products

Remediation

Vendor solution

Update to patched version

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner M-Files Corporation
Published Nov 20, 2024
Updated Feb 23, 2026
Reserved Oct 18, 2024
CISA Vulnrichment
Updated Nov 20, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner M-Files Corporation
Published Nov 20, 2024
Updated Feb 23, 2026
Exploited since n/a
EUVD-2024-33488