CVE-2021-32651
Dashboard / Vulnerabilities / CVE-2021-32651
Summary:
Details: OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the application and explore the LDAP tree using Blind LDAP Injection techniques. The specific payload depends on how the User Search Filter property is configured in OneDev. This issue was fixed in version 4.4.2.
References: https://github.com/theonedev/onedev/commit/4440f0c57e440488d7e653417b2547eaae8ad19c, https://github.com/theonedev/onedev/security/advisories/GHSA-5864-2496-4xjf
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v4.4.1
v4.4.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
