LDAP Authentication Bypass in Hazelcast IMDG and Jet Products
CVE-2020-26168
9.8CRITICAL
What is CVE-2020-26168?
The LDAP authentication method within the LdapLoginModule of Hazelcast IMDG Enterprise and Jet products exhibits a flaw that allows user authentication without proper password verification in certain user scenarios. This issue can lead to unauthorized access, permitting clients and members to authenticate even when incorrect credentials are provided, thereby compromising the security of the system.
