GHSA-mg2c-rc36-p594
CRITICALCVE-2021-43350An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.
- Affected
- >= 5.1.0, < 5.1.4, >= 6.0.0, < 6.0.1
- Fixed in
- 5.1.4
- Weakness
- CWE-74
- Published
- 2022-05-24
- Source
- github