—
GO-2024-2776
Apache Traffic Control Traffic Ops Vulnerable to LDAP Injection in github.com/apache/trafficcontrol
Quick fix
GO-2024-2776 — github.com/apache/trafficcontrol: upgrade to the fixed version with the command below.
go get github.com/apache/trafficcontrol@v5.1.4+incompatibleDetails
Apache Traffic Control Traffic Ops Vulnerable to LDAP Injection in github.com/apache/trafficcontrol
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/apache/trafficcontrol
Introduced in:
5.1.0+incompatibleFixed in: 5.1.4+incompatibleFix
go get github.com/apache/trafficcontrol@v5.1.4+incompatibleReferences
- https://github.com/advisories/GHSA-mg2c-rc36-p594[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2021-43350[ADVISORY]
- http://www.openwall.com/lists/oss-security/2021/11/11/3[WEB]
- http://www.openwall.com/lists/oss-security/2021/11/11/4[WEB]
- http://www.openwall.com/lists/oss-security/2021/11/17/1[WEB]
- https://trafficcontrol.apache.org/security[WEB]