Логотип exploitDog
bind:CVE-2020-9495
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-9495

Количество 2

Количество 2

nvd логотип

CVE-2020-9495

больше 5 лет назад

Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDAP filter used to query the LDAP users. By measuring the response time for the login request, arbitrary attribute data can be retrieved from LDAP user objects.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-v83p-xwm9-v4g8

почти 4 года назад

Injection in Apache Archiva

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-9495

Apache Archiva login service before 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDAP filter used to query the LDAP users. By measuring the response time for the login request, arbitrary attribute data can be retrieved from LDAP user objects.

CVSS3: 5.3
27%
Средний
больше 5 лет назад
github логотип
GHSA-v83p-xwm9-v4g8

Injection in Apache Archiva

CVSS3: 5.3
27%
Средний
почти 4 года назад

Уязвимостей на страницу