Loading HuntDB...

GHSA-4p4p-22cr-2gqw

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load on the directory server, leading to denial of service. Encoding has been added for user-provided fragments that are used when constructing the LDAP query. No publicly available exploits are known.

Related CVEs

Key Information

GHSA ID
GHSA-4p4p-22cr-2gqw
Published
January 8, 2024 9:30 AM
Last Modified
January 8, 2024 9:30 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 9, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.