WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied userna
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacke
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special ele
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm c
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP synt
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Lima
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Do
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector pas
maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the au
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology
Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) construc
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim ano
ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was di
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the Cle
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Sof
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Boun
LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escap
LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constru
A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/ca
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection
Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, inst
Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domai
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated att
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ge
n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP n
mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmw
A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When a
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `or
An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDA
If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This l
Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter
An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensit
A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstAct
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A
Frequently Asked Questions
What is CWE-90?
CWE-90 (CWE-90) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-90?
There are 43 CVE records associated with CWE-90 in our database. Of these, 5 are critical severity, 15 are high severity, and 15 are medium severity.
How can I protect against CWE-90 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-90 using AI-powered security agents.
Detect CWE-90 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-90 vulnerabilities across your infrastructure.
Get Started