Impact
Netatalk software versions 2.1.0 through 4.4.2 contain an LDAP filter injection flaw that permits an authenticated attacker to craft LDAP filter strings to manipulate queries, retrieve limited information, or modify LDAP entries. The weakness is identified as CWE‑90.
Affected Systems
The affected product is Netatalk, released by the Netatalk project, with vulnerable releases ranging from version 2.1.0 to 4.4.2.
Risk and Exploitability
The CVSS score of 4.2 indicates moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Since Netatalk exposes LDAP filtering over the network, the likely attack vector is remote over the service interface by an authenticated user; this is inferred from the requirement for authentication described in the product’s vulnerable behavior.
OpenCVE Enrichment