v2.6.1.1 (Released Oct 8, 2021)

2 years ago

v2.6.1.1 - Oct 8, 2021



Security update

This release is a patch to v2.6.1.0, and addresses an LDAP authentication vulnerability in YCQL.

If you can't update to immediately, and you're running YugabyteDB in conjunction with LDAP authentication for YCQL, disable LDAP authentication for YCQL by setting the --ycql_use_ldap flag to false, which reverts the authentication method to hashed password. YSQL is not affected.

