QID 980718
QID 980718: Nodejs (npm) Security Update for ldapauth (GHSA-82mg-x548-gq3j)
Versions 2.2.4 and earlier of `ldapauth-fork` are affected by an LDAP injection vulnerability. This allows an attacker to inject and run arbitrary LDAP commands via the username parameter.
## Recommendation
ldapauth is not actively maintained, having not seen a publish since 2014. As a result, there is no patch available. Consider updating to use [ldapauth-fork](https://www.npmjs.com/package/ldapauth-fork) 2.3.3 or greater.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-82mg-x548-gq3j for updates pertaining to this vulnerability.
Vendor References
- GHSA-82mg-x548-gq3j -
github.com/advisories/GHSA-82mg-x548-gq3j
CVEs related to QID 980718
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-82mg-x548-gq3j | ldapauth |
|
|
| GHSA-82mg-x548-gq3j | ldapauth-fork |
|