Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker
High severity
GitHub Reviewed
Published
Nov 2, 2021
in
StevenWeathers/thunderdome-planning-poker
•
Updated Feb 8, 2024
Package
Affected versions
< 1.16.3
Patched versions
1.16.3
Description
Published by the National Vulnerability Database
Nov 2, 2021
Reviewed
Nov 2, 2021
Published to the GitHub Advisory Database
Nov 8, 2021
Last updated
Feb 8, 2024
Impact
LDAP injection vulnerability, only affects instances with LDAP authentication enabled.
Patches
Patch for vulnerability released with v1.16.3.
Workarounds
Disable LDAP feature if in use
References
OWASP LDAP Injection Prevention Cheat Sheet
For more information
If you have any questions or comments about this advisory:
References