CVE-2021-3027
Last modified
CVE-2021-3027 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Librit | Passhport | <= 2.5 |
References
- https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1Patch, Third Party Advisory
- https://github.com/LibrIT/passhport/pull/562Patch, Third Party Advisory
- https://jorgectf.gitlab.io/disclosure/cve-2021-3027/Third Party Advisory
- https://github.com/LibrIT/passhport/commit/366b03f607729c4538e91b634ecc57c8398522a1Patch, Third Party Advisory
- https://github.com/LibrIT/passhport/pull/562Patch, Third Party Advisory
- https://jorgectf.gitlab.io/disclosure/cve-2021-3027/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3027?
How severe is CVE-2021-3027?
How do I fix CVE-2021-3027?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-30264Possible use after free due improper validation of reference…6.7
- CVE-2021-30265Possible memory corruption due to improper validation of mem…6.7
- CVE-2021-30266Possible use after free due to improper memory validation wh…6.7
- CVE-2021-30267Possible integer overflow to buffer overflow due to improper…7.8
- CVE-2021-30268Possible heap Memory Corruption Issue due to lack of input v…7.8
- CVE-2021-30269Possible null pointer dereference due to lack of TLB validat…7.8
- CVE-2021-30270Possible null pointer dereference in thread profile trap han…7.8
- CVE-2021-30271Possible null pointer dereference in trap handler due to lac…7.8
- CVE-2021-30272Possible null pointer dereference in thread cache operation …7.8
- CVE-2021-30273Possible assertion due to improper handling of IPV6 packet w…7.5
- CVE-2021-30274Possible integer overflow in access control initialization i…7.8
- CVE-2021-30275Possible integer overflow in page alignment interface due to…7.8
Are you affected by CVE-2021-3027?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
