app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.
References
Link | Resource |
---|---|
https://jorgectf.gitlab.io/disclosure/cve-2021-3027/ | Third Party Advisory |
https://github.com/LibrIT/passhport/pull/562 | Patch Third Party Advisory |
https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1 | Patch Third Party Advisory |
Configurations
Information
Published : 2021-03-25 20:16
Updated : 2022-05-03 09:04
NVD link : CVE-2021-3027
Mitre link : CVE-2021-3027
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
librit
- passhport