Lucene search

K
osvGoogleOSV:CVE-2021-32651
HistoryJun 01, 2021 - 6:15 p.m.

CVE-2021-32651

2021-06-0118:15:07
Google
osv.dev
3
onedev
development operations platform
ldap
external authentication
version 4.4.1
blind ldap injection

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

23.4%

OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the application and explore the LDAP tree using Blind LDAP Injection techniques. The specific payload depends on how the User Search Filter property is configured in OneDev. This issue was fixed in version 4.4.2.

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

23.4%

Related for OSV:CVE-2021-32651