{"id":"GHSA-82mg-x548-gq3j","summary":"LDAP Injection in ldapauth","details":"Versions 2.2.4 and earlier of `ldapauth-fork` are affected by an LDAP injection vulnerability. This allows an attacker to inject and run arbitrary LDAP commands via the username parameter.\n\n\n\n## Recommendation\n\nldapauth is not actively maintained, having not seen a publish since 2014. As a result, there is no patch available. Consider updating to use [ldapauth-fork](https://www.npmjs.com/package/ldapauth-fork) 2.3.3 or greater.","aliases":["CVE-2015-7294"],"modified":"2023-11-08T03:57:59.693271Z","published":"2020-08-31T22:49:46Z","database_specific":{"cwe_ids":["CWE-90"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:07:59Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7294"},{"type":"WEB","url":"https://github.com/vesse/node-ldapauth-fork/issues/21"},{"type":"WEB","url":"https://github.com/vesse/node-ldapauth-fork/commit/3feea43e243698bcaeffa904a7324f4d96df60e4"},{"type":"PACKAGE","url":"https://github.com/vesse/node-ldapauth-fork"},{"type":"WEB","url":"https://www.npmjs.com/advisories/18"},{"type":"WEB","url":"https://www.npmjs.com/advisories/19"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/09/18/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/09/18/8"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/09/21/2"}],"affected":[{"package":{"name":"ldapauth-fork","ecosystem":"npm","purl":"pkg:npm/ldapauth-fork"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-82mg-x548-gq3j/GHSA-82mg-x548-gq3j.json"}},{"package":{"name":"ldapauth","ecosystem":"npm","purl":"pkg:npm/ldapauth"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c 2.2.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-82mg-x548-gq3j/GHSA-82mg-x548-gq3j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}