CVE-2021-43350 is a critical LDAP injection vulnerability affecting Apache Traffic Control Traffic Ops, allowing an unauthenticated attacker to inject unsanitized content into the LDAP filter via a specially crafted username to the POST /login endpoint. With a CVSS score of 9.8, this vulnerability presents a critical risk due to its network attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high FAUCET Risk Score of 80/100 indicates its significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.1.0, < 5.1.4CPE matchmatch criteria | cpe:2.3:a:apache:traffic_control:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.1CPE matchmatch criteria | cpe:2.3:a:apache:traffic_control:*:*:*:*:*:*:*:* | ||
5.1.4CPE matchmatch criteria | cpe:2.3:a:apache:traffic_control:5.1.4:rc0:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:a:apache:traffic_control:6.0.1:rc0:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.