Improper Authentication in Avalanche - CVE-2021-22962
Published: January 15, 2024 / Updated: January 15, 2024
Avalanche
Ivanti
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests within the allowPassThrough method. A remote attacker can send a specially crafted request, bypass authentication process and gain unauthorized access to the application.