Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8750

Опубликовано: 12 дек. 2016
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.

Apache Karaf uses the LDAPLoginModule to authenticate users to a directory via LDAP. It does not, however, encode usernames properly and hence is vulnerable to LDAP injection attacks. While it appears that it is not possible to exploit this vulnerability to allow an attacker to gain remote access, it does allow an attacker to insert special characters into the search query step. Therefore, it can potentially be exploited as part of a Denial of Service attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6karafAffected
Red Hat OpenStack Platform 10 (Newton)opendaylightWill not fix
Red Hat OpenStack Platform 11 (Ocata)opendaylightWill not fix
Red Hat OpenStack Platform 12 (Pike)opendaylightWill not fix
Red Hat OpenStack Platform 13 (Queens)opendaylightAffected
Red Hat OpenStack Platform 8 (Liberty)opendaylightWill not fix
Red Hat OpenStack Platform 9 (Mitaka)opendaylightWill not fix
Red Hat JBoss A-MQ 6.3karafFixedRHSA-2018:132203.05.2018
Red Hat JBoss Fuse 6.3karafFixedRHSA-2018:132203.05.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-90
https://bugzilla.redhat.com/show_bug.cgi?id=1524432karaf: LDAP injection in LDAPLoginModule

EPSS

Процентиль: 81%
0.0151
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 8 лет назад

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.

CVSS3: 6.5
debian
почти 8 лет назад

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate u ...

CVSS3: 6.5
github
около 7 лет назад

Moderate severity vulnerability that affects org.apache.karaf:apache-karaf

EPSS

Процентиль: 81%
0.0151
Низкий

7.5 High

CVSS3