Impact
The vulnerability arises from improper neutralisation of special elements in LDAP queries within the ldap-auth plugin of Apache APISIX. A user who has valid credentials for one LDAP entry can construct a request that causes the plugin to authenticate them as a different consumer whose identity was not intended to be reachable under the plugin's configured scope. This results in successful impersonation and unauthorized access to services protected by APISIX.
Affected Systems
Affected products are Apache APISIX users running versions from 2.11.0 through 3.17.0. The vendor is the Apache Software Foundation, and the vulnerability exists in the ldap-auth plugin. All deployments that rely on this plugin within the specified version range are susceptible.
Risk and Exploitability
The CVSS base score of 7 indicates a high severity. Because an attacker only needs a valid credential for another LDAP entry and the plugin lacks proper query sanitisation, the exploit is relatively straightforward. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA's KEV catalog, but the high CVSS and potential for credential hopping warrant immediate attention.
OpenCVE Enrichment