Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-91651
HistoryNov 03, 2021 - 12:00 a.m.

Thunderdome injection vulnerability

2021-11-0300:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
thunderdome
injection vulnerability
ldap authentication
steven weathers
agile planning poker
open source

EPSS

0.003

Percentile

70.1%

Thunderdome is an open source agile planning poker application with an interesting theme by Steven Weathers, an individual developer in the U.S. An injection vulnerability exists in Thunderdome, which stems from the LDAP authentication feature not properly escaping the provided username, and no details of the vulnerability are currently available.

EPSS

0.003

Percentile

70.1%