CVE-2024-33868
CRITICALDescription
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.
Is your site exposed to CVE-2024-33868?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| linqi | linqi |
| microsoft | windows |
References
Frequently Asked Questions
What is CVE-2024-33868? +
How severe is CVE-2024-33868? +
What products are affected by CVE-2024-33868? +
How do I check if I'm vulnerable to CVE-2024-33868? +
Related Vulnerabilities
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input …
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, …
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the …
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to …
When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is …