MEDIUM6.5
GHSA-qfr5-wjpw-q4c4
Denial of Service in python-ldap
Quick fix
GHSA-qfr5-wjpw-q4c4 — python-ldap: upgrade to the fixed version with the command below.
pip install --upgrade 'python-ldap>=3.4.0'Details
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
Are you affected?
Enter the version of the package you're using.