mitmproxy
cpe:2.3:a:mitmproxy:mitmproxy:*:*:*:*:*:*:*
- <= 12.2.1
A vulnerability exists in mitmproxy versions through 12.2.1 in the built-in LDAP proxy authentication. The issue arises because the username is not properly sanitized before querying the LDAP server, allowing a malicious client to bypass authentication. This vulnerability affects only mitmproxy instances that have the proxyauth option enabled for LDAP, a setting that is not activated by default.
Exploitation of this vulnerability allows for unauthorized access by bypassing LDAP authentication.
Users can upgrade to mitmproxy version 12.2.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.