Emmanuel Lécharny created DIRAPI-461:
----------------------------------------
Summary: Rdn.unescapeValue mis-decodes specials and silently drops
invalid escapes
Key: DIRAPI-461
URL: https://issues.apache.org/jira/browse/DIRAPI-461
Project: Directory Client API
Issue Type: Bug
Affects Versions: 2.1.8
Reporter: Emmanuel Lécharny
Fix For: 2.1.9
An application extracts the *CN* from a client-certificate subject *DN* and
calls _Rdn.unescapeValue_ after validating the escaped text contains no
forbidden name '_admin_'; the attacker presents *CN* text '_ad\\zmin_' or
'_a\\4zdmin'_-shaped escapes — validation on the raw text finds no match, but
_unescapeValue_ silently decodes into '_admin_' and the application authorizes
the attacker.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]