CVE Published: 19/02/2018 |
CVE Updated: 17/09/2024 |
CVE Year: 2016 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Karaf Status : PUBLISHED
CVE-2016-8750 Description
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.