domains plugin password not validated --> security issue

General discussion about Plugins for Cacti

Moderators: Developers, Moderators

Post Reply
rdobroun
Posts: 4
Joined: Fri Sep 24, 2010 7:37 pm

domains plugin password not validated --> security issue

Post by rdobroun »

Hi all,

I'm running cacti 0.8.8a and added domains plugin 0.1.
After configuring all LDAP parameters im able to login if the username is existing, however the password is not validated so I can enter whatever I want and am logged in.

When using the normal buildt in single LDAP auth fuction everything works like normal and I can only login if username and password are correct and matching.

does anyone have the same problem??
What do I need to do / provide to further troubleshoot the cause??

This is the Domain config in the multi domain settings page:
cacti-ldap.JPG
cacti-ldap.JPG (100.56 KiB) Viewed 1822 times
I have also tried the fix mentioned in this post:
http://forums.cacti.net/viewtopic.php?f ... in#p208150
but this seems bo also be fixed by removing the entries from the LDAP Auth config page in Configuration --> Settings --> Authentication.

regards
Rupert
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest