PT-2025-48812 · Opsre · Go-Ldap-Admin
28Hus
·
Published
2025-12-03
·
Updated
2025-12-03
·
CVE-2025-13948
CVSS v3.1
5.6
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
opsre go-ldap-admin versions prior to 20251011
Description
A security issue exists in opsre go-ldap-admin. The problem relates to the processing of the file
docs/docker-compose/docker-compose.yaml within the JWT Handler component. Manipulation of the secret key argument can result in the use of a hard-coded cryptographic key. This attack can be initiated remotely and is considered highly complex with difficult exploitability. The exploit details have been publicly disclosed and may be used maliciously.Recommendations
Update opsre go-ldap-admin to a version later than 20251011.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Go-Ldap-Admin