Description
An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4555 | An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter. |
Github GHSA |
GHSA-mg2c-rc36-p594 | Apache Traffic Control Traffic Ops Vulnerable to LDAP Injection |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T03:55:28.477Z
Reserved: 2021-11-03T00:00:00.000Z
Link: CVE-2021-43350
No data.
Status : Modified
Published: 2021-11-11T13:15:07.737
Modified: 2024-11-21T06:29:07.007
Link: CVE-2021-43350
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA