LDAP injection in Apache Kerby - CVE-2023-25613

 

LDAP injection in Apache Kerby - CVE-2023-25613

Published: February 22, 2023


Vulnerability identifier: #VU72492
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25613
CWE-ID: CWE-90
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to improper input validation when processing DLAP queries in LdapIdentityBackend. A remote non-authenticated attacker can send a specially crafted LDAP query to the application, bypass authentication process and gain unauthorized access to the application.


Affected software

Apache Kerby
Oracle Communications Cloud Native Configuration Console
QRadar User Behavior Analytics
Cloudera Data Platform Private Cloud Base for IBM

How to mitigate CVE-2023-25613

Install updates from vendor's website.

Apache Kerby - update to 2.0.3
QRadar User Behavior Analytics - update to 4.1.16
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.3 HF2

External References

Related Security Bulletins