HIGH 8.1 Go
Improper Neutralization of Special Elements used in an LDAP Query in stevenweathers/thunderdome-planning-poker
GHSA-26cm-qrc6-mfgj · CVE-2021-41232 · GO-2022-0939
Published · Modified
Description
Impact
LDAP injection vulnerability, only affects instances with LDAP authentication enabled.
Patches
Patch for vulnerability released with v1.16.3.
Workarounds
Disable LDAP feature if in use
References
OWASP LDAP Injection Prevention Cheat Sheet
For more information
If you have any questions or comments about this advisory:
- Open an issue in Thunderdome Github Repository
- Email us at steven@weathers.me
References
- WEB https://github.com/StevenWeathers/thunderdome-planning-poker/security/advisories/GHSA-26cm-qrc6-mfgj
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-41232
- WEB https://github.com/github/securitylab/issues/464#issuecomment-957094994
- WEB https://github.com/StevenWeathers/thunderdome-planning-poker/commit/f1524d01e8a0f2d6c3db5461c742456c692dd8c1
- PACKAGE https://github.com/StevenWeathers/thunderdome-planning-poker
Ready to move
Start Securing
Free, no credit card | First findings in minutes