PT-2022-27680 · Apache · Apache Manifoldcf
4Ra1N
·
Published
2022-12-07
·
Updated
2025-04-22
·
CVE-2022-45910
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ManifoldCF versions 2.23 and prior versions
Description
The issue is related to improper neutralization of special elements used in an LDAP query, also known as 'LDAP Injection'. This allows an attacker to manipulate the LDAP search queries, potentially leading to denial of service (DoS), execution of additional queries, or filter manipulation during user lookup. The vulnerability occurs when the username or the domain string are passed to the UserACLs servlet without validation in the ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF.
Recommendations
For Apache ManifoldCF versions 2.23 and prior, update to a version that includes the fix for this issue.
As a temporary workaround, consider validating the username and domain string before passing them to the UserACLs servlet to prevent LDAP injection attacks.
Restrict access to the UserACLs servlet to minimize the risk of exploitation.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Manifoldcf