Lucene search

K
osvGoogleOSV:GHSA-CHJ8-5XGW-WCVJ
HistoryJan 07, 2019 - 7:14 p.m.

Moderate severity vulnerability that affects org.apache.karaf:apache-karaf

2019-01-0719:14:46
Google
osv.dev
12

EPSS

0.002

Percentile

57.7%

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.

EPSS

0.002

Percentile

57.7%