Impact
Apache Karaf’s LDAPCache and LDAPBackingEngine create search filters by textual substitution of placeholders %u, %dn, and %fqdn into administrator‑defined templates. The only sanitization performed was doubling backslashes, leaving unescaped LDAP filter meta‑characters such as *, (, ), and NUL. A username containing these characters can alter the structure of the resulting filter, turning an equality comparison into a wildcard or closing an expression prematurely. This can cause a user or role lookup to match unintended LDAP entries, potentially granting unauthorized access or roles.
Affected Systems
The vulnerability exists in Apache Karaf. No specific version range is listed, so all builds that include the affected LDAPCache and LDAPBackingEngine components are potentially impacted. The lack of version detail means users should verify whether their installation includes the mentioned components and apply a fix when available.
Risk and Exploitability
The vulnerability’s severity is not formally scored, but it introduces a high‑impact injection flaw (CWE‑90) that could be leveraged to gain unintended LDAP access. The absence of a KEV listing and lack of publicly disclosed exploits indicate that it is likely not yet abused in the wild, but the mechanism is straightforward and could be weaponized quickly once a patch is unavailable.
OpenCVE Enrichment