An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/apache/trafficcontrol(Go) | 6.0.0 | 6.0.1 | N/A |
| github.com/apache/trafficcontrol(Go) | 5.1.0 | 5.1.4 | N/A |
CVSS Metrics