目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-90 LDAP查询中使用的特殊元素转义处理不恰当(LDAP注入) 类漏洞列表 74

CWE-90 LDAP查询中使用的特殊元素转义处理不恰当(LDAP注入) 类弱点 74 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-90 指 LDAP 注入漏洞,属于输入验证缺陷。攻击者通过构造包含特殊字符的恶意输入,篡改后端 LDAP 查询逻辑,从而绕过身份验证或窃取敏感数据。开发者应严格对用户输入进行白名单校验,避免直接拼接查询语句,并使用参数化查询或转义特殊字符,确保输入被视作数据而非可执行代码,从而有效防御此类攻击。

MITRE CWE 官方描述
CWE:CWE-90 LDAP 查询中特殊元素的不当中和('LDAP Injection') 英文:产品使用来自上游组件的外部可影响输入来构造 LDAP 查询的全部或部分内容,但在将查询发送给下游组件时,未对可能修改预期 LDAP 查询的特殊元素进行中和,或中和不当。
常见影响 (1)
Confidentiality, Integrity, Availability Execute Unauthorized Code or Commands, Read Application Data, Modify Application Data
An attacker could include input that changes the LDAP query which allows unintended commands or code to be executed, allows sensitive data to be read or modified or causes other unintended behavior.
缓解措施 (1)
Implementation Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range…
代码示例 (1)
The code below constructs an LDAP query using user input address data:
context = new InitialDirContext(env); String searchFilter = "StreetAddress=" + address; NamingEnumeration answer = context.search(searchBase, searchFilter, searchCtls);
Bad · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2023-29050 Open-Xchange App Suite 安全漏洞 — OX App Suite 7.6 High 2024-01-08
CVE-2023-6905 NxFilter 注入漏洞 — NxFilter 4.3 Medium 2023-12-17
CVE-2023-3447 WordPress plugin Active Directory Integration/LDAP Integration 注入漏洞 — Active Directory Integration / LDAP Integration 7.6 High 2023-06-29
CVE-2023-28853 Mastodon 注入漏洞 — mastodon 7.7 High 2023-04-04
CVE-2022-4254 SSSD 注入漏洞 — SSSD 8.1 - 2023-02-01
CVE-2015-10027 TTRSS-Auth-LDAP 注入漏洞 — TTRSS-Auth-LDAP 5.5 Medium 2023-01-07
CVE-2022-45910 Apache ManifoldCF 注入漏洞 — Apache ManifoldCF 8.2 - 2022-12-07
CVE-2021-43782 Tuleap 注入漏洞 — tuleap 6.7 Medium 2021-12-15
CVE-2021-43350 Apache Traffic Control 注入漏洞 — Apache Traffic Control 9.8 - 2021-11-11
CVE-2021-41232 Thunderdome 注入漏洞 — thunderdome-planning-poker 8.1 High 2021-11-02
CVE-2021-32651 Theonedev Onedev 注入漏洞 — onedev 3.1 Low 2021-06-01
CVE-2020-5246 Traccar GPS Tracking System 注入漏洞 — Traccar 7.7 High 2020-07-14
CVE-2020-5281 Perun 注入漏洞 — perun 6.2 Medium 2020-03-25
CVE-2019-11277 Cloud Foundry NFS Volume Service 注入漏洞 — CF NFS volume release 8.1 - 2019-09-23

CWE-90(LDAP查询中使用的特殊元素转义处理不恰当(LDAP注入)) 是常见的弱点类别,本平台收录该类弱点关联的 74 条 CVE 漏洞。