Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfpv-rrgm-4qqr

Опубликовано: 12 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

EPSS

Процентиль: 34%
0.00406
Низкий

7.4 High

CVSS3

Дефекты

CWE-235
CWE-89

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
redhat
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
nvd
3 месяца назад

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

CVSS3: 7.4
debian
3 месяца назад

When safe filter is used with variable expansion, all following pipeli ...

suse-cvrf
около 2 месяцев назад

Security update for dovecot24

EPSS

Процентиль: 34%
0.00406
Низкий

7.4 High

CVSS3

Дефекты

CWE-235
CWE-89