CVE-2021-32651
Published on: 06/01/2021 12:00:00 AM UTC
Last Modified on: 06/16/2021 02:28:00 PM UTC
Certain versions of Onedev from Onedev Project contain the following vulnerability:
OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions 4.4.1 and prior, an attacker can manipulate a user search filter to send forged queries to the application and explore the LDAP tree using Blind LDAP Injection techniques. The specific payload depends on how the User Search Filter property is configured in OneDev. This issue was fixed in version 4.4.2.
- CVE-2021-32651 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
theonedev - onedev version <= 4.4.1
CVSS3 Score: 4.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
LDAP injection via OneDev may leak some LDAP directory information · Advisory · theonedev/onedev · GitHub | github.com text/html |
![]() |
Fix issue #304 - Potential information leak via Ldap injection when ldap · theonedev/[email protected] · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Onedev Project | Onedev | All | All | All | All |
- cpe:2.3:a:onedev_project:onedev:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-32651 : OneDev is a development operations platform. If the LDAP external authentication mechanism is enab… twitter.com/i/web/status/1… | 2021-06-01 17:19:22 |
![]() |
CVE-2021-32651 | 2021-06-01 17:41:32 |