logo

CVE-2015-7294 ldapauth

Package

Manager: npm
Name: ldapauth
Vulnerable Version: >=0 <2.2.4

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.01317 pctl0.79081

Details

LDAP Injection in ldapauth Versions 2.2.4 and earlier of `ldapauth-fork` are affected by an LDAP injection vulnerability. This allows an attacker to inject and run arbitrary LDAP commands via the username parameter. ## Recommendation ldapauth is not actively maintained, having not seen a publish since 2014. As a result, there is no patch available. Consider updating to use [ldapauth-fork](https://www.npmjs.com/package/ldapauth-fork) 2.3.3 or greater.

Metadata

Created: 2020-08-31T22:49:46Z
Modified: 2021-09-23T19:58:02Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-82mg-x548-gq3j/GHSA-82mg-x548-gq3j.json
CWE IDs: ["CWE-90"]
Alternative ID: GHSA-82mg-x548-gq3j
Finding: F107
Auto approve: 1