The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4725 | The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet. |
Github GHSA |
GHSA-p9qj-4rjp-j3w9 | Apache Directory Studio Command Injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T06:41:09.261Z
Reserved: 2015-07-01T00:00:00
Link: CVE-2015-5349
No data.
Status : Deferred
Published: 2016-04-11T21:59:06.070
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-5349
OpenCVE Enrichment
No data.
EUVD
Github GHSA