Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-41232

Опубликовано: 02 нояб. 2021
Источник: nvd
CVSS3: 8.1
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is not properly escaped. This issue has been patched in version 1.16.3. If users are unable to update they should disable the LDAP feature if in use.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:thunderdome:planning_poker:*:*:*:*:*:*:*:*
Версия до 1.16.3 (исключая)

EPSS

Процентиль: 65%
0.00492
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74
CWE-74

Связанные уязвимости

CVSS3: 8.1
github
около 4 лет назад

Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker

EPSS

Процентиль: 65%
0.00492
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74
CWE-74