[SECURITY] CVE-2020-9495: Apache Archiva login service is vulnerable to LDAP injection

Martin <[email protected]> Fri, 19 Jun 2020 20:31:22 +0200
Newsgroups gmane.comp.apache.sling.user,gmane.comp.apache.incubator.ranger.devel,gmane.comp.security.bugtraq,gmane.comp.apache.maven.announce,gmane.comp.security.oss.general
Message-ID <2640261.krIbtSRUe9__20488.8363414042$1592593334$gmane$org@golgafrichnam>
CVE-2020-9495: Apache Archiva login service is vulnerable to LDAP injection

Severity: Medium

Vendor:
The Apache Software Foundation

Versions Affected:

    Apache Archiva all versions before 2.2.5

By providing special values to the archiva login form a attacker is able to retrieve user attribute data from the connected LDAP server. 
With certain characters it is possible to modify the LDAP filter used to query the users on the connected LDAP server. 
By measuring the response time, arbitrary attribute data can be retrieved from LDAP user objects.

Mitigation:

    Upgrade to Apache Archiva 2.2.5 or higher

References:
http://archiva.apache.org/security.html#CVE-2020-9495

The newest Archiva version can be downloaded from:
http://archiva.apache.org/download.cgi