Hall of Fame
Back to Hall of Fame Contents Back to WeKan Website

DirectoryGroupBleed

CVEIconVulnerability nameDate Responsible Security Disclosure byStarsProcessVulnerabilities
-

DirectoryGroupBleed 2026-09-27 xet7 Gold starGold starGold star Found and fixed during the sibling authentication audit following the LDAP disclosure.

LDAP direct user-bind mode skipped configured login-group restrictions, and a group query could omit its membership clause when a user attribute was missing. CAS matched allowed group names as substring regular expressions, allowing similarly named groups. Both LDAP modes now enforce membership, missing identities fail closed, and CAS compares complete literal CN values. LDAP filter and DN values are escaped for their respective contexts.

CWE-863. High severity for deployments relying on the affected group restrictions. No CVE assigned.

Fix prepared for the Upcoming release.

Details

LDAP and CAS group refusals are summarized as DirectoryGroupBleed in Admin Panel / Problems. Escaping legitimate identifier punctuation does not itself record an attack.

Source fix and regression coverage

Verification

Positive and negative tests execute the LDAP handler and CAS validator. Coverage includes allowed and denied members, missing membership values, service-account lookup order, no fallback after group denial, escaped DNs, prefix collisions, regex metacharacters, empty allowlists and query-injection values.

The authentication regression run passed 46 focused Node suites and five Chromium scenarios. The local Meteor application rebuilt successfully. Live OpenLDAP/Active Directory, external CAS/SAML providers, Sandstorm and the FerretDB authentication matrix were not tested.

Authentication audit, findings and limitations