Branch: refs/heads/2.1.0
Home:
https://github.com/tribe29/checkmk
Commit: eb8921dd09100916b573d118c40a0ae38a8e63b8
https://github.com/tribe29/checkmk/commit/eb8921dd09100916b573d118c40a0ae38…
Author: Hannes Rantzsch <hannes.rantzsch(a)tribe29.com>
Date: 2022-08-23 (Tue, 23 Aug 2022)
Changed paths:
A .werks/14382
M cmk/gui/plugins/userdb/ldap_connector.py
Log Message:
-----------
14382 SEC Don't leak LDAP server address when connection fails
Prior to this Werk, trying to authenticate to an LDAP server that is unavailable would
result in an error saying that the server could be contacted.
This leaks the address of the LDAP server.
In addition, it was possible to check if a user is a htpasswd user, since the LDAP
connection is not attempted for these users and LDAP error is not shown.
Now a generic "invalid login" message is shown to avoid this information
disclosure.
Change-Id: I538fe904cee3a4036a051fa34b8ea224420a089d