CVE-2022-31084
In versions prior to 8.0 There are cases where LAM instantiates objects from arbitrary classes.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LAM instantiates objects from arbitrary classes. An attacker can inject the first constructor argument. This can lead to code execution if non-LAM classes are instantiated that execute code during object creation. This issue has been fixed in version 8.0.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.41% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-88
- Affected
- ldap-account-manager/ldap account manager · debian/debian linux
- Source
- security-advisories@github.com
References
- https://github.com/LDAPAccountManager/lam/commit/f1d5d04952f39a1b4ea203d3964fa88e1429dfd4Patch, Third Party Advisory
- https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-r387-grjx-qgvwThird Party Advisory
- https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations/Exploit, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5177Third Party Advisory
- https://github.com/LDAPAccountManager/lam/commit/f1d5d04952f39a1b4ea203d3964fa88e1429dfd4Patch, Third Party Advisory
- https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-r387-grjx-qgvwThird Party Advisory
- https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations/Exploit, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5177Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.