CVE-2021-41232
Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is not properly escaped. This issue has been patched in version 1.16.3. If users are unable to update they should disable the LDAP feature if in use.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L
- EPSS probability
- 0.49%
- CWE
- CWE-90, CWE-74
- Published
- 2021-11-02
- Last modified
- 2026-03-13
Affected products
- StevenWeathers thunderdome-planning-poker
Weakness type
Related vulnerabilities
- CVE-2024-56841 — A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab
- CVE-2026-33289 — SuiterCRM has LDAP Filter Injection in Authentication Module
- CVE-2019-11277 — Volume Services is vulnerable to an LDAP injection attack
- CVE-2026-46619 — OpenAM Authentication Bypass via MSISDN LDAP Injection
- CVE-2023-28853 — Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
- CVE-2020-5246 — LDAP injection vulnerability in Traccar GPS Tracking System
- CVE-2023-29050 — The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to ac
- CVE-2026-41919 — Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction