{"api_version":"1","generated_at":"2026-07-24T22:45:45+00:00","cve":"CVE-2021-3027","urls":{"html":"https://cve.report/CVE-2021-3027","api":"https://cve.report/api/cve/CVE-2021-3027.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-3027","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-3027"},"summary":{"title":"CVE-2021-3027","description":"app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-03-26 03:16:00","updated_at":"2022-05-03 16:04:00"},"problem_types":["CWE-74"],"metrics":[],"references":[{"url":"https://jorgectf.gitlab.io/disclosure/cve-2021-3027/","name":"https://jorgectf.gitlab.io/disclosure/cve-2021-3027/","refsource":"MISC","tags":[],"title":"jorgectf - jorgectf","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1","name":"https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1","refsource":"MISC","tags":[],"title":"Update user.py · LibrIT/passhport@366b03f · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/LibrIT/passhport/pull/562","name":"https://github.com/LibrIT/passhport/pull/562","refsource":"MISC","tags":[],"title":"Polish LDAP Injection fix by jorgectf · Pull Request #562 · LibrIT/passhport · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-3027","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3027","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"3027","vulnerable":"1","versionEndIncluding":"2.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"librit","cpe5":"passhport","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-3027","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://jorgectf.gitlab.io/disclosure/cve-2021-3027/","url":"https://jorgectf.gitlab.io/disclosure/cve-2021-3027/"},{"refsource":"MISC","name":"https://github.com/LibrIT/passhport/pull/562","url":"https://github.com/LibrIT/passhport/pull/562"},{"refsource":"MISC","name":"https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1","url":"https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1"}]}},"nvd":{"publishedDate":"2021-03-26 03:16:00","lastModifiedDate":"2022-05-03 16:04:00","problem_types":["CWE-74"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:librit:passhport:*:*:*:*:*:*:*:*","versionEndIncluding":"2.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"3027","Ordinal":"197405","Title":"CVE-2021-3027","CVE":"CVE-2021-3027","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"3027","Ordinal":"1","NoteData":"app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"3027","Ordinal":"2","NoteData":"2021-03-25","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"3027","Ordinal":"3","NoteData":"2021-12-24","Type":"Other","Title":"Modified"}]}}}