CVE-2022-29155 is a critical SQL injection vulnerability affecting OpenLDAP versions 2.x before 2.5.12 and 2.6.x before 2.6.2, specifically within the experimental back-sql backend. This flaw allows an unauthenticated attacker to execute arbitrary SQL statements during an LDAP search operation due to improper escaping of search filters. With a CVSS score of 9.8 (Critical), this vulnerability poses a severe risk of complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), its high FAUCET Risk Score of 93/100 and mention in media coverage indicate significant concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.5.12CPE matchmatch criteria | cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:* | ||
>= 2.6.0, < 2.6.2CPE matchmatch criteria | cpe:2.3:a:openldap:openldap:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Enterprise - October 2024
Oct 14, 2024AS-2022-012: OpenLDAP
Aug 29, 2022In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2 a SQL injection vulnerability exists in the experimental back-sql backend to slapd via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed due to a lack of proper escaping.
May 10, 2022openldap: OpenLDAP SQL injection
May 4, 2022