Impact
Fabric CA, the Certificate Authority used in Hyperledger Fabric, has a flaw in its Client.GetUser function when an LDAP backend is active. The username supplied by HTTP Basic authentication is embedded directly into the LDAP uid UserFilter without escaping LDAP metacharacters. An unauthenticated attacker with network access to the CA enrollment endpoint can alter this filter before the password check and potentially redirect authentication attempts toward a victim account.
Affected Systems
Versions of hyperledger fabric-ca older than 1.5.21 that are configured to use an LDAP backend are vulnerable. Deployments running the patched 1.5.21 release or those that do not use LDAP for identity management are not affected.
Risk and Exploitability
The CVSS base score of 6.3 indicates a moderate threat level. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, suggesting a very low probability of widespread automated exploitation. The vulnerability can be exploited by any actor with network access to the CA enrollment endpoint by sending a crafted HTTP request; no additional privileges are needed, making the attack relatively straightforward for an exposed deployment.
OpenCVE Enrichment
Github GHSA