fix: reject empty passwords in LDAP authentication to prevent unauthenticated binds (#23633)
Per RFC 4513, a Simple Bind with a non-empty DN but empty password is unauthenticated simple authentication. Many LDAP servers (OpenLDAP default, some AD configs) accept these binds, allowing account takeover without valid credentials. Rejects empty and whitespace-only passwords before attempting the LDAP bind.
This commit is contained in:
@@ -323,6 +323,14 @@ async def ldap_auth(
|
||||
detail=ERROR_MESSAGES.ACTION_PROHIBITED,
|
||||
)
|
||||
|
||||
# Reject empty passwords before attempting the LDAP bind.
|
||||
# Per RFC 4513 §5.1.2, a Simple Bind with a non-empty DN but empty
|
||||
# password is "unauthenticated simple authentication" — many LDAP
|
||||
# servers (OpenLDAP default, some AD configs) return success for these,
|
||||
# which would grant access without valid credentials.
|
||||
if not form_data.password or not form_data.password.strip():
|
||||
raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
|
||||
|
||||
# NOW load LDAP config variables
|
||||
LDAP_SERVER_LABEL = request.app.state.config.LDAP_SERVER_LABEL
|
||||
LDAP_SERVER_HOST = request.app.state.config.LDAP_SERVER_HOST
|
||||
|
||||
Reference in New Issue
Block a user