oss-sec mailing list archives

CVE-2023-25613: LDAP Injection Vulnerability in Apache Kerby


From: Colm O hEigeartaigh <coheigea () apache org>
Date: Mon, 20 Feb 2023 10:15:04 +0000

Description:

An LDAP Injection vulnerability exists in the LdapIdentityBackend of
Apache Kerby before 2.0.3.

Credit:

4ra1n of Chaitin Tech (finder)

References:

https://directory.apache.org/
https://www.cve.org/CVERecord?id=CVE-2023-25613


Current thread: