First published: Mon Dec 04 2017(Updated: )
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/karaf | <4.0.8 | 4.0.8 |
Apache Karaf | <4.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Apache Karaf vulnerability is CVE-2016-8750.
The severity level of CVE-2016-8750 is medium with a CVSS score of 6.5.
CVE-2016-8750 affects Apache Karaf versions prior to 4.0.8.
CVE-2016-8750 allows LDAP injection attacks, potentially leading to a denial of service.
To fix CVE-2016-8750, upgrade Apache Karaf to version 4.0.8 or later.