CVE-2020-5281: LDAP connector injection in Perun
Published Mar 25, 2020
·Updated
In Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from Perun LDAP. Issue is fixed in version 3.9.1 by sanitisation of the input.
Affected Software
1 affected component
CESNET Perun<3.9.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Perunto a version that resolves this vulnerability.Fixed in 3.9.1
Event History
Mar 25, 2020
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-5281?
CVE-2020-5281 has a medium severity rating.
2
How do I fix CVE-2020-5281?
To fix CVE-2020-5281, upgrade to Perun version 3.9.1 or later.
3
Who is affected by CVE-2020-5281?
Users of Perun versions prior to 3.9.1 are affected by CVE-2020-5281.
4
What is the nature of the vulnerability in CVE-2020-5281?
CVE-2020-5281 allows a VO or group manager to improperly modify LDAP extSource configuration.
5
What measures have been taken to address CVE-2020-5281?
CVE-2020-5281 has been addressed through input sanitization in the updated version.