CVE-2018-18389

CVE-2018-18389

Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.

Source: CVE-2018-18389

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다