CVE-2015-10027 is a critical LDAP injection vulnerability affecting the Username Handler component of hydrian TTRSS-Auth-LDAP. This flaw allows for arbitrary LDAP query manipulation, potentially leading to unauthorized access or information disclosure. With a CVSS score of 9.8 (Critical), it is easily exploitable over the network without authentication and can result in complete compromise of confidentiality, integrity, and availability. While there are no known public exploits or active exploitation, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.5CPE matchmatch criteria | cpe:2.3:a:ttrrs-auth-ldap_project:ttrrs-auth-ldap:0.5:rc1:*:*:*:*:*:* | ||
0.5CPE matchmatch criteria | cpe:2.3:a:ttrrs-auth-ldap_project:ttrrs-auth-ldap:0.5:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.