Apache Directory Studio Command Injection
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Dec 7, 2023
Package
Affected versions
< 2.0.0.v20151221-M10
Patched versions
2.0.0.v20151221-M10
Description
Published by the National Vulnerability Database
Apr 11, 2016
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Aug 1, 2023
Last updated
Dec 7, 2023
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.
References