app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.
References
Link | Resource |
---|---|
https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1 | Patch Third Party Advisory |
https://github.com/LibrIT/passhport/pull/562 | Patch Third Party Advisory |
https://jorgectf.gitlab.io/disclosure/cve-2021-3027/ | Third Party Advisory |
https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1 | Patch Third Party Advisory |
https://github.com/LibrIT/passhport/pull/562 | Patch Third Party Advisory |
https://jorgectf.gitlab.io/disclosure/cve-2021-3027/ | Third Party Advisory |
Configurations
History
21 Nov 2024, 06:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1 - Patch, Third Party Advisory | |
References | () https://github.com/LibrIT/passhport/pull/562 - Patch, Third Party Advisory | |
References | () https://jorgectf.gitlab.io/disclosure/cve-2021-3027/ - Third Party Advisory |
Information
Published : 2021-03-26 03:16
Updated : 2024-11-21 06:20
NVD link : CVE-2021-3027
Mitre link : CVE-2021-3027
CVE.ORG link : CVE-2021-3027
JSON object : View
Products Affected
librit
- passhport
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')