Impact
The user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration.
Patches
The issue is fixed in version 8.0.
Workarounds
Allow admin access via fixed list instead of LDAP search.
For more information
If you have any questions or comments about this advisory:
Credits
Arseniy Sharoglazov
Impact
The user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration.
Patches
The issue is fixed in version 8.0.
Workarounds
Allow admin access via fixed list instead of LDAP search.
For more information
If you have any questions or comments about this advisory:
Credits
Arseniy Sharoglazov