Description
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
3GHSAModerate severity vulnerability that affects org.apache.karaf:apache-karaf↗2019-01-07 ▶ OSVModerate severity vulnerability that affects org.apache.karaf:apache-karaf↗2019-01-07 ▶ CVEListCVE-2016-8750: Apache Karaf prior to 4↗2018-02-19 ▶ 📋Vendor Advisories
1Red Hatkaraf: LDAP injection in LDAPLoginModule↗2016-12-12 ▶ 💬Community
2BugzillaCVE-2016-8750 karaf: LDAP injection in LDAPLoginModule↗2017-12-11 ▶ BugzillaCVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c↗2016-01-08 ▶