Lucene search

K
osvGoogleOSV:USN-5424-1
HistoryMay 17, 2022 - 11:47 a.m.

openldap vulnerability

2022-05-1711:47:37
Google
osv.dev
5
openldap
sql injection
back-sql backend
remote attacker
database

AI Score

7.9

Confidence

Low

EPSS

0.013

Percentile

86.0%

It was discovered that OpenLDAP incorrectly handled certain SQL statements
within LDAP queries in the experimental back-sql backend. A remote attacker
could possibly use this issue to perform an SQL injection attack and alter
the database.