Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTgybWcteDU0OC1ncTNq
LDAP Injection in ldapauth
Versions 2.2.4 and earlier of ldapauth-fork
are affected by an LDAP injection vulnerability. This allows an attacker to inject and run arbitrary LDAP commands via the username parameter.
Recommendation
ldapauth is not actively maintained, having not seen a publish since 2014. As a result, there is no patch available. Consider updating to use ldapauth-fork 2.3.3 or greater.
Permalink: https://github.com/advisories/GHSA-82mg-x548-gq3jJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTgybWcteDU0OC1ncTNq
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 4 years ago
Updated: about 2 years ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Percentage: 0.00222
EPSS Percentile: 0.60514
Identifiers: GHSA-82mg-x548-gq3j, CVE-2015-7294
References:
- https://github.com/vesse/node-ldapauth-fork/issues/21
- https://github.com/vesse/node-ldapauth-fork/commit/3feea43e243698bcaeffa904a7324f4d96df60e4
- https://www.npmjs.com/advisories/18
- https://www.npmjs.com/advisories/19
- http://www.openwall.com/lists/oss-security/2015/09/18/4
- https://nvd.nist.gov/vuln/detail/CVE-2015-7294
- http://www.openwall.com/lists/oss-security/2015/09/18/8
- http://www.openwall.com/lists/oss-security/2015/09/21/2
- https://github.com/advisories/GHSA-82mg-x548-gq3j
Blast Radius: 23.0
Affected Packages
npm:ldapauth
Dependent packages: 9Dependent repositories: 44
Downloads: 95 last month
Affected Version Ranges: < 2.2.4
No known fixed version
All affected versions: 1.0.0, 1.0.1, 1.0.2, 2.0.0, 2.1.0, 2.2.0, 2.2.1, 2.2.2, 2.2.3
npm:ldapauth-fork
Dependent packages: 52Dependent repositories: 1,169
Downloads: 133,554 last month
Affected Version Ranges: < 2.3.3
Fixed in: 2.3.3
All affected versions: 2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2.8, 2.2.9, 2.2.10, 2.2.11, 2.2.12, 2.2.13, 2.2.14, 2.2.15, 2.2.16, 2.2.17, 2.2.18, 2.2.19, 2.3.0, 2.3.1, 2.3.2
All unaffected versions: 2.3.3, 2.4.0, 2.5.0, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5, 3.0.0, 3.0.1, 4.0.0, 4.0.1, 4.0.2, 4.1.0, 4.1.1, 4.2.0, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 6.0.0, 6.1.0