CVE Published: 11/11/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Traffic Control Status : PUBLISHED
CVE-2021-43350 Description
An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.
CWE-ID: CWE-90 CWE Name: CWE-90 Improper Neutralization of Special Elements used in an LDAP Query (
LDAP Injection
) Source: Apache Software Foundation
Common Attack Pattern Enumeration and Classification (CAPEC)