An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apache traffic control 6.0.1 |
||
apache traffic control |
||
apache traffic control 5.1.4 |