CRITICAL
Support for authentication bypass condition in M-Files LDAP authentication
Published Nov 20, 2024
9.2
CRITICALCVSS 4.0
EPSS 0.61%
Description
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
Affected products
-
- Version 0StatusaffectedConstraints<24.11
- Version 0StatusunaffectedConstraints<24.8 LTS SR2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| M-Files Corporation | M-Files Server | unaffected |
|
OR
- < 24.8.13981.13
- < 24.11
-
- Version 0StatusaffectedConstraints<24.11
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to patched version
Weaknesses (1)
References (3)
- https://empower.m-files.com/security-advisories/CVE-2024-10127 vendor-advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-33488 Advisory
- https://product.m-files.com/security-advisories/CVE-2024-10127 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://empower.m-files.com/security-advisories/CVE-2024-10127 | vendor-advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-33488 | Advisory | |
| https://product.m-files.com/security-advisories/CVE-2024-10127 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner M-Files Corporation
Published Nov 20, 2024
Updated Feb 23, 2026
Reserved Oct 18, 2024
Link CVE-2024-10127
CISA Vulnrichment
Updated Nov 20, 2024
ENISA EUVD
EUVD-2024-33488 Assigner M-Files Corporation
Published Nov 20, 2024
Updated Feb 23, 2026
Exploited since n/a
Link EUVD-2024-33488