Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-45046

Опубликовано: 05 дек. 2022
Источник: redhat

Описание

This flaw targets the camel-ldap package. According to the maintainers this CVE should be retracted soon.

Меры по смягчению последствий

Maintainers have added a documentation detail regarding LDAP Injection in Camel LDAP component. Please check the link for more information. https://github.com/apache/camel/blob/3ea0740370bb436dcf70b91dcbfb4e2177fca797/components/camel-ldap/src/main/docs/ldap-component.adoc

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3org.apache.camel-camelNot affected
Red Hat build of Quarkusio.quarkus.platform-quarkus-platform-configNot affected
Red Hat Fuse 7com.redhat.fuse.eap-fuse-eapNot affected
Red Hat Fuse 7org.apache.camel-camelNot affected
Red Hat Fuse 7org.wildfly.camel.example-example-camelNot affected
Red Hat Fuse 7org.wildfly.camel-wildfly-camelNot affected
Red Hat Integration Camel K 1org.apache.camel-camelNot affected
Red Hat Integration Camel K 1org.apache.camel.kafkaconnector-camel-kafka-connector-aggregatorNot affected
Red Hat Integration Camel K 1org.apache.camel.quarkus-camel-quarkusNot affected
Red Hat Integration Camel Quarkus 1org.apache.camel-camelNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-90
https://bugzilla.redhat.com/show_bug.cgi?id=2150871camel-ldap: LDAP Injection on camel-ldap component when using the filter option

Связанные уязвимости

nvd
около 3 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

CVSS3: 9.8
github
около 3 лет назад

camel-ldap component allows LDAP Injection when using the filter option