GHSA-mg2c-rc36-p594
Dashboard / Vulnerabilities / GHSA-mg2c-rc36-p594
GHSA-mg2c-rc36-p594
Summary: Apache Traffic Control Traffic Ops Vulnerable to LDAP Injection
Details: An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST `/login` endpoint of any API version to inject unsanitized content into the LDAP filter.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-43350, https://github.com/apache/trafficcontrol, https://pkg.go.dev/vuln/GO-2024-2776, https://trafficcontrol.apache.org/security, http://www.openwall.com/lists/oss-security/2021/11/11/3, http://www.openwall.com/lists/oss-security/2021/11/11/4, http://www.openwall.com/lists/oss-security/2021/11/17/1
Affected packages
Package
Name: github.com/apache/trafficcontrol
Purl: pkg:golang/github.com/apache/trafficcontrol
Affected ranges
Type: SEMVER
Events:
