All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.
{ "nvd_published_at": "2021-02-11T12:15:00Z", "severity": "HIGH", "github_reviewed_at": "2021-04-01T23:39:38Z", "github_reviewed": true, "cwe_ids": [ "CWE-74", "CWE-90" ] }