PT-2025-48812 · Opsre · Go-Ldap-Admin

28Hus

·

Published

2025-12-03

·

Updated

2025-12-03

·

CVE-2025-13948

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions opsre go-ldap-admin versions prior to 20251011
Description A security issue exists in opsre go-ldap-admin. The problem relates to the processing of the file docs/docker-compose/docker-compose.yaml within the JWT Handler component. Manipulation of the secret key argument can result in the use of a hard-coded cryptographic key. This attack can be initiated remotely and is considered highly complex with difficult exploitability. The exploit details have been publicly disclosed and may be used maliciously.
Recommendations Update opsre go-ldap-admin to a version later than 20251011.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-13948

Affected Products

Go-Ldap-Admin