LDAP Injection Vulnerability in Apache Archiva Login Service
CVE-2020-9495
Key Information:
- Vendor
Apache
- Status
- Vendor
- CVE Published:
- 19 June 2020
Badges
What is CVE-2020-9495?
The login service in Apache Archiva versions prior to 2.2.5 is susceptible to LDAP injection attacks. An attacker can exploit this vulnerability by entering specially crafted input into the login form. This input can manipulate the LDAP filter, potentially exposing sensitive user attribute data stored in the connected LDAP server. By analyzing the response times of login attempts, adversaries can gain unauthorized access to critical information about LDAP user objects, posing a significant risk to data integrity and privacy.
Affected Version(s)
Apache Archiva Apache Archiva 2.2.4 and below
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
27% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved