On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could get valid LDAP credentials.
Solution:
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.usom.gov.tr/bildirim/tr-21-0795 | third party advisory |
https://pentest.blog/liderahenk-0day-all-your-pardus-clients-belongs-to-me/ | third party advisory exploit |