[ 
https://issues.apache.org/jira/browse/DIRAPI-483?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Emmanuel Lécharny resolved DIRAPI-483.
--------------------------------------
    Resolution: Fixed

Fixed with commit b6383b7bef82b0b880e1b38846b0d0dbcc0f10a1 

> Programmatic Ava/Rdn constructors accept structural characters in attribute 
> type
> --------------------------------------------------------------------------------
>
>                 Key: DIRAPI-483
>                 URL: https://issues.apache.org/jira/browse/DIRAPI-483
>             Project: Directory Client API
>          Issue Type: Bug
>    Affects Versions: 2.1.8
>            Reporter: Emmanuel Lécharny
>            Priority: Minor
>             Fix For: 2.1.9
>
>
> A self-service portal builds each user's entry *DN* as _new Dn(new Rdn(null, 
> userChosenAttr, userChosenValue), baseDn) _and passes _dn.getName()_ to a 
> privileged _add_/_modify_ connection.
> The attacker submits _userChosenAttr = "cn=probe,ou=admins"_, and the 
> resulting *DN* string re-parses with an injected leaf under a different 
> _subtree_, letting the attacker place or address entries outside their 
> assigned container



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to