First published: Thu Mar 25 2021(Updated: )
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ForgeRock OpenAM | <13.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29156 is a vulnerability in ForgeRock OpenAM versions before 13.5.1 that allows LDAP injection via the Webfinger protocol.
CVE-2021-29156 allows an unauthenticated attacker to perform character-by-character retrieval of password hashes, retrieve a session token, or a private key.
CVE-2021-29156 has a severity rating of 7.5 (high).
To fix CVE-2021-29156, upgrade ForgeRock OpenAM to version 13.5.1 or later.
Yes, you can find more information about CVE-2021-29156 at the following references: [1] [2]