In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Authentication Bypass vulnerabilities in an interactive lesson.
Start learningUpgrade pyramid-ldap3
to version 0.3.2 or higher.
pyramid-ldap3 is a project that provides LDAP authentication services for Pyramid application.
Affected versions of this package are vulnerable to Authentication Bypass. The login
value in the search filter wasn't properly escaped in the authenticate()
method.
In earlier versions it was possible login with a different user name like foo*
instead of foobar
.