Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r89m-qpxm-ccgx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the application and explore the LDAP tree using Blind LDAP Injection techniques. The specific payload depends on how the User Search Filter property is configured in OneDev. This issue was fixed in version 4.4.2.

OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the application and explore the LDAP tree using Blind LDAP Injection techniques. The specific payload depends on how the User Search Filter property is configured in OneDev. This issue was fixed in version 4.4.2.

EPSS

Процентиль: 48%
0.00247
Низкий

Дефекты

CWE-90

Связанные уязвимости

CVSS3: 3.1
nvd
больше 4 лет назад

OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the application and explore the LDAP tree using Blind LDAP Injection techniques. The specific payload depends on how the User Search Filter property is configured in OneDev. This issue was fixed in version 4.4.2.

CVSS3: 4.3
fstec
больше 4 лет назад

Уязвимость платформы совместной разработки OneDev, связанная с непринятием мер по нейтрализации специальных элементов в запросе LDAP, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 48%
0.00247
Низкий

Дефекты

CWE-90