Description
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.
Problem types
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
Product status
Any version before 8.19
Credits
Joshua Rogers
References
github.com/...ommit/0b0e16c3eae28bbf453d33a81a9c58ce7db6d5bb
wekan.fi/
www.vulncheck.com/...an-ldap-authentication-filter-injection