5
CVSSv2

CVE-2020-9495

Published: 19/06/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Apache Archiva login service prior to 2.2.5 is vulnerable to LDAP injection. A attacker is able to retrieve user attribute data from the connected LDAP server by providing special values to the login form. With certain characters it is possible to modify the LDAP filter used to query the LDAP users. By measuring the response time for the login request, arbitrary attribute data can be retrieved from LDAP user objects.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache archiva

Github Repositories

CVE-2020-9495 PoC CVE-2020-9495 is medium severity LDAP injection vulnerability in Apache Archiva versions before 225 It allows an attacker to retrieve any LDAP attribute values of users that exist on the LDAP server From the official Apache Archiva advisory: By providing special values to the archiva login form a attacker is able to retrieve user attribute data from the c