CVE-2022-29155: SQL Injection
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29155?
CVE-2022-29155 is a SQL injection vulnerability in OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, allowing SQL statements within an LDAP query.
How does CVE-2022-29155 occur?
CVE-2022-29155 occurs when a SQL statement is included in an LDAP search filter, due to a lack of proper escaping.
What is the severity of CVE-2022-29155?
CVE-2022-29155 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2022-29155?
OpenLDAP versions 2.x before 2.5.12 and 2.6.x before 2.6.2 are affected by CVE-2022-29155.
How can I fix CVE-2022-29155?
Update to OpenLDAP version 2.5.12 or later to fix CVE-2022-29155.