PAC4J versions prior to 4.5.10, 5.7.10, and 6.4.1 contain an LDAP Injection vulnerability affecting multiple methods within the library. A low-privileged remote attacker can inject malicious LDAP syntax into ID-based search parameters to execute unauthorized LDAP queries and perform arbitrary directory operations against vulnerable systems. The vulnerability is rated HIGH severity with a CVSS 3.1 score of 8.8, indicating significant risk. The attack requires network access with low privileges but minimal complexity, and carries high impact across confidentiality, integrity, and availability of affected systems. No user interaction is required for exploitation. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. With an EPSS score of 0.0014, the probability of exploitation in the wild is low relative to other disclosed vulnerabilities. Organizations should prioritize patching to the fixed versions listed above, particularly for systems handling sensitive directory information.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0, < 4.5.10CPE match | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | ||
>= 5.0, < 5.7.10CPE match | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.4.1CPE match | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.5.10CPE matchmatch criteria | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.7.10CPE matchmatch criteria | cpe:2.3:a:pac4j:pac4j:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.