Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
3.2.4
-
None
-
None
-
Unknown
Description
When using JAX-RS search with the LdapQueryVisitor, we don't encode the query value by default. This means that an LDAP injection attack is possible. By default we should encode query values (and make it configurable if the user wants to support searching using wildcards for example).
Attachments
Attachments
Issue Links
- links to