CVE-2016-8750: Medium severity apache karaf vulnerability
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
Other sources
Apache Karaf uses the LDAPLoginModule to authenticate users to a directory via LDAP. However, it is not encoding usernames properly and hence is vulnerable to LDAP injection attacks.
While it appears that it not possible to exploit this vulnerability to allow an attacker to gain remote access, it allows an attacker to insert special characters into the search query step. Therefore, it can potentially be exploited as part of a Denial Of Service attack.
External References:
https://karaf.apache.org/security/cve-2016-8750.txt
Upstream patch:
https://github.com/apache/karaf/commit/ac07cb2440ceff94b3001728c1611fc471253d19
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache Karaf vulnerability?
The vulnerability ID for this Apache Karaf vulnerability is CVE-2016-8750.
What is the severity level of CVE-2016-8750?
The severity level of CVE-2016-8750 is medium with a CVSS score of 6.5.
How does CVE-2016-8750 affect Apache Karaf?
CVE-2016-8750 affects Apache Karaf versions prior to 4.0.8.
What is the impact of CVE-2016-8750?
CVE-2016-8750 allows LDAP injection attacks, potentially leading to a denial of service.
How can I fix CVE-2016-8750 in Apache Karaf?
To fix CVE-2016-8750, upgrade Apache Karaf to version 4.0.8 or later.