https://t.co/z7WPg3HtJY (CodeQL query to detect XSLT injections) was received under the All For One bounty program and is now merged! Congrats @ggolawski! Want to contribute and be rewarded? See https://t.co/UsVq1OUOew
I've recently found and reported couple of LDAP injection vulnerabilities:
- CVE-2020-1958 in Apache Druid
- CVE-2020-9495 in Apache Archiva
- CVE-2020-5246 in Traccar
- CVE-2020-5281 in Perun
Here's the writeup about the first one, CVE-2020-1958 in Druid: https://t.co/wc5OiIo3RD
[CVE-2020-1958]: Apache Druid LDAP injection vulnerability: Posted by Jonathan Wei on Apr 01Severity: High Vendor: The Apache Software Foundation Versions Affected: Druid 0.17.0 Description: When LDAP authentication is enabled: - Callers of Druid APIs… https://t.co/wHs0KqZxfX
Join the GitHub Security Lab Slack workspace, to know more about our bounty programs, to learn how to write CodeQL, to give feedback , and to discuss all things security: https://t.co/Y2UuoZEJXU
Awesome CodeQL query from @ggolawski that detects many variants of LDAP Injections in Java: Plain Java JNDI, UnboundID, Spring LDAP and Apache LDAP API. We are pleased to award him our maximum bounty reward $3000
https://t.co/rvdMkektz2