Lucene search

K
osvGoogleOSV:GHSA-26CM-QRC6-MFGJ
HistoryNov 08, 2021 - 6:16 p.m.

Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker

2021-11-0818:16:21
Google
osv.dev
6
ldap injection
vulnerability
patch
v1.16.3
workaround
disable
owasp
cheat sheet
thunderdome
github
repository
email

EPSS

0.003

Percentile

70.1%

Impact

LDAP injection vulnerability, only affects instances with LDAP authentication enabled.

Patches

Patch for vulnerability released with v1.16.3.

Workarounds

Disable LDAP feature if in use

References

OWASP LDAP Injection Prevention Cheat Sheet

For more information

If you have any questions or comments about this advisory:

EPSS

0.003

Percentile

70.1%

Related for OSV:GHSA-26CM-QRC6-MFGJ