Only server-side SSH implementations that include the optional sshd-ldap component and configure it for password or public-key authentication against LDAP are affected. Apache MINA SSHD servers that do not use sshd-ldap, or do not use it for those authentication methods, are not affected.
The issue is remotely exploitable without prior authentication or user interaction. Successful authentication was possible using the username "*" and password "*" because LDAP filter metacharacters were not escaped.
Affected releases are Apache MINA SSHD 1.2.0 through 2.19.0 and 3.0.0-M1 through 3.0.0-M5. Upgrade affected applications to 2.20.0 or 3.0.0-M6, which escape LDAP filter parameters according to RFC 4515.
Remove or disable sshd-ldap for password and public-key authentication where feasible. Deployments that do not use this optional LDAP authentication component are not affected.