PAC4J
cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*
- >= 4, <= 4.5.10
- >= 5, <= 5.7.10
- >= 6, <= 6.4.1
A vulnerability allowing LDAP injection has been identified in PAC4J versions 4.0 prior to 4.5.10, 5.0 prior to 5.7.10, and 6.0 prior to 6.4.1. This vulnerability arises in multiple methods where a low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters. Such injection could lead to unauthorized LDAP queries and arbitrary operations within the directory.
Exploitation of this vulnerability could result in unauthorized LDAP queries and arbitrary directory operations, potentially affecting the integrity and confidentiality of directory data.
Users should upgrade to PAC4J version 4.5.10 or newer, 5.7.10 or newer, or 6.4.1 or newer, depending on their current version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.