HIGH
LDAP connector injection in Perun
Published Mar 25, 2020
7.5
HIGHCVSS 3.1
EPSS 1.36%
Description
In Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from Perun LDAP. Issue is fixed in version 3.9.1 by sanitisation of the input.
Affected products
-
- Version < 3.9.1StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-26477 Advisory
- https://github.com/CESNET/perun/commit/ac527bc3225a64208ee5cee59e5918ee360ca039 x_refsource_MISCPatchThird Party Advisory
- https://github.com/CESNET/perun/pull/2635 x_refsource_MISCPatchThird Party Advisory
- https://github.com/CESNET/perun/security/advisories/GHSA-gj88-9q3f-72m3 x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-26477 | Advisory | |
| https://github.com/CESNET/perun/commit/ac527bc3225a64208ee5cee59e5918ee360ca039 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/CESNET/perun/pull/2635 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/CESNET/perun/security/advisories/GHSA-gj88-9q3f-72m3 | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 25, 2020
Updated Aug 4, 2024
Reserved Jan 2, 2020
Link CVE-2020-5281
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-26477 Assigner GitHub_M
Published Mar 25, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-26477