You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Severity: MediumDiscovered: 28 of February-2022, 02:06 PM
CWE ID
CWE-90
CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Details
An unhandled LDAP error has been reflected in the response from the server.
This information might help attackers execute LDAP Injection attacks and expose sensitive information.
Attacked Parameter:
Attacked Parameter Type: MultiParse::DataType::String
Attacked Parameter Location: Query
Triggered Using Token: U+0000
Parameter Encoding: [:none]
Possible exposure
Execute Unauthorized Code or Commands; Read Application Data; Modify Application Data
Remediation suggestions
Use a whitelist of acceptable inputs and assume all input is malicious. Meaning that application should avoid copying user-controllable data into LDAP queries. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules.
LDAP Error
Severity:
Medium
Discovered:28 of February-2022, 02:06 PM
CWE ID
CWE-90
CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Details
An unhandled LDAP error has been reflected in the response from the server.
This information might help attackers execute LDAP Injection attacks and expose sensitive information.
Attacked Parameter:
Attacked Parameter Type: MultiParse::DataType::String
Attacked Parameter Location: Query
Triggered Using Token: U+0000
Parameter Encoding: [:none]
Possible exposure
Execute Unauthorized Code or Commands; Read Application Data; Modify Application Data
Remediation suggestions
Use a whitelist of acceptable inputs and assume all input is malicious. Meaning that application should avoid copying user-controllable data into LDAP queries. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules.
Request
Response
External links
The text was updated successfully, but these errors were encountered: