VYPR
Critical severity9.8NVD Advisory· Published Nov 11, 2021· Updated Jun 17, 2026

CVE-2021-43350

CVE-2021-43350

Description

An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/apache/trafficcontrolGo
>= 6.0.0, < 6.0.16.0.1
github.com/apache/trafficcontrolGo
>= 5.1.0, < 5.1.45.1.4

Affected products

5
  • cpe:2.3:a:apache:traffic_control:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:apache:traffic_control:*:*:*:*:*:*:*:*range: >=5.1.0,<5.1.4
    • cpe:2.3:a:apache:traffic_control:5.1.4:rc0:*:*:*:*:*:*
    • cpe:2.3:a:apache:traffic_control:6.0.1:rc0:*:*:*:*:*:*
    • (no CPE)range: Traffic Ops
  • ghsa-coords
    Range: >= 6.0.0, < 6.0.1

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.