Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32923
HistoryNov 12, 2021 - 2:41 a.m.

LDAP Injection

2021-11-1202:41:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
29

0.006 Low

EPSS

Percentile

78.7%

github.com/apache/trafficcontrol is vulnerable to LDAP injection. An attacker is able to send malicious username to the the login or post endpoint of any API version, inject unsanitized content into the LDAP filter, allowing the malicious query injection.

0.006 Low

EPSS

Percentile

78.7%