Skip to content

LDAP unprotected search query during certificate based authentication #6199

@progier389

Description

@progier389

Issue Description

During certificate based client authentication, certmap may be configured to use the user cert's subjectDN to look for a match. The SubjectDN is however not escaped and may provides unexpected search result.

Package Version and Platform:

  • Platform: Fedora
  • Package and version: main branch
  • Browser: N/A

Steps to Reproduce
See https://issues.redhat.com/browse/IDMDS-3959

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions