LDAP / Active Directory Integration
Anyone without logging in could send specially crafted text to the search tool used for finding user accounts. This would allow them to discover extra information about the network that they should not normally be able to see. They could not change any information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksA working example has been published, so assume someone will try.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate LDAP / Active Directory Integration to 2.2.1.
For developers: what the fix changed
The release diff is linked below. No summary of the fix has been written for this one.