LDAP injection vulnerability, only affects instances with LDAP authentication enabled.
Patch for vulnerability released with v1.16.3.
Disable LDAP feature if in use
OWASP LDAP Injection Prevention Cheat Sheet
If you have any questions or comments about this advisory:
github.com/github/securitylab/issues/464#issuecomment-957094994
github.com/StevenWeathers/thunderdome-planning-poker
github.com/StevenWeathers/thunderdome-planning-poker/commit/f1524d01e8a0f2d6c3db5461c742456c692dd8c1
github.com/StevenWeathers/thunderdome-planning-poker/security/advisories/GHSA-26cm-qrc6-mfgj
nvd.nist.gov/vuln/detail/CVE-2021-41232