Lucene search

K
osvGoogleOSV:GHSA-MG2C-RC36-P594
HistoryMay 24, 2022 - 7:20 p.m.

Apache Traffic Control Traffic Ops Vulnerable to LDAP Injection

2022-05-2419:20:26
Google
osv.dev
3

7.2 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.7%

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.

7.2 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.7%