Fabric CA 是 Hyperledger Fabric 的证书颁发机构(Certificate Authority)。在版本 1.5.21 之前,当 fabric-ca 配置了 LDAP 后端时,位于 中的 函数在将 HTTP 基本认证中的用户名插入 LDAP uid 搜索的 UserFilter 时,未对 LDAP 元字符进行转义。拥有 CA 注册端点网络访问权限的未认证攻击者,可以在密码验证之前操纵 LDAP 搜索,从而将认证尝试引导至目标账户。未使用 LDAP 后端的部署不受此问题影响。该问题已在版本
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| hyperledger | fabric-ca | < 1.5.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hyperledger | fabric-ca | < 1.5.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet