{"id":"CVE-2015-7294","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-7294","summary":"LDAP Injection in ldapauth","details":"Versions 2.2.4 and earlier of `ldapauth-fork` are affected by an LDAP injection vulnerability. This allows an attacker to inject and run arbitrary LDAP commands via the username parameter.\n\n\n\n## Recommendation\n\nldapauth is not actively maintained, having not seen a publish since 2014. As a result, there is no patch available. Consider updating to use [ldapauth-fork](https://www.npmjs.com/package/ldapauth-fork) 2.3.3 or greater.","published":"2020-08-31T22:49:46Z","modified":"2023-11-08T03:57:59.693271Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"ldapauth-fork","fixedVersion":"2.3.3"},{"ecosystem":"npm","name":"ldapauth","fixedVersion":null}],"fix":{"url":"https://github.com/vesse/node-ldapauth-fork/commit/3feea43e243698bcaeffa904a7324f4d96df60e4","label":"vesse/node-ldapauth-fork@3feea43"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7294"},{"type":"WEB","url":"https://github.com/vesse/node-ldapauth-fork/issues/21"},{"type":"WEB","url":"https://github.com/vesse/node-ldapauth-fork/commit/3feea43e243698bcaeffa904a7324f4d96df60e4"},{"type":"PACKAGE","url":"https://github.com/vesse/node-ldapauth-fork"},{"type":"WEB","url":"https://www.npmjs.com/advisories/18"},{"type":"WEB","url":"https://www.npmjs.com/advisories/19"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/09/18/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/09/18/8"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/09/21/2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:59.693271Z"}}