First published: Wed Mar 25 2020(Updated: )
In Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from Perun LDAP. Issue is fixed in version 3.9.1 by sanitisation of the input.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cesnet Perun | <3.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5281 has a medium severity rating.
To fix CVE-2020-5281, upgrade to Perun version 3.9.1 or later.
Users of Perun versions prior to 3.9.1 are affected by CVE-2020-5281.
CVE-2020-5281 allows a VO or group manager to improperly modify LDAP extSource configuration.
CVE-2020-5281 has been addressed through input sanitization in the updated version.