Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Implement proper input sanitization to prevent LDAP injection attacks #153

Merged
merged 1 commit into from
Dec 4, 2023

Conversation

tam1m
Copy link
Contributor

@tam1m tam1m commented Dec 4, 2023

This patch sanitizes the username input by replacing unsafe characters with their ASCII HEX representation. This is necessary to counteract potential injections of malicious statements into the LDAP search query constructed by the plugin.

Table of unsafe characters and their replacements:

\	\\5c
*	\\2a
(	\\28
)	\\29
NUL	\\00

References:
https://datatracker.ietf.org/doc/html/rfc4515#section-3
https://cheatsheetseries.owasp.org/cheatsheets/LDAP_Injection_Prevention_Cheat_Sheet.html#search-filter-escaping

@joshuaboniface joshuaboniface merged commit 5b2b6d8 into jellyfin:master Dec 4, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants