securesauce / precli

Precaution CLI - command line static application security testing tool
https://precli.readthedocs.io/
Other
13 stars 3 forks source link

New rules for an anonymous LDAP bind #444

Open ericwb opened 3 months ago

ericwb commented 3 months ago

Is your feature request related to a problem? Please describe. In LDAP, anonymous bind is equivalent to no authentication at all. This is insecure as anyone can access the LDAP data without login.

Describe the solution you'd like New rules for each language to check for LDAP bind that is anonymous.

Describe alternatives you've considered n/a

Additional context

Love this idea? Give it a 👍. We prioritize fulfilling features with the most 👍.

ericwb commented 1 month ago

Python version is merged as rule PY527