GHSA-82mg-x548-gq3j

Suggest an improvement
Source
https://github.com/advisories/GHSA-82mg-x548-gq3j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-82mg-x548-gq3j/GHSA-82mg-x548-gq3j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-82mg-x548-gq3j
Aliases
  • CVE-2015-7294
Published
2020-08-31T22:49:46Z
Modified
2023-11-08T03:57:59Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
LDAP Injection in ldapauth
Details

Versions 2.2.4 and earlier of ldapauth-fork are affected by an LDAP injection vulnerability. This allows an attacker to inject and run arbitrary LDAP commands via the username parameter.

Recommendation

ldapauth is not actively maintained, having not seen a publish since 2014. As a result, there is no patch available. Consider updating to use ldapauth-fork 2.3.3 or greater.

Database specific
{
    "cwe_ids":  [
        "CWE-90"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:07:59Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / ldapauth-fork

Package

Name
ldapauth-fork
View open source insights on deps.dev
Purl
pkg:npm/ldapauth-fork

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-82mg-x548-gq3j/GHSA-82mg-x548-gq3j.json"

npm / ldapauth

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

last_known_affected_version_range
"< 2.2.4"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-82mg-x548-gq3j/GHSA-82mg-x548-gq3j.json"