An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.
| Software | From | Fixed in |
|---|---|---|
| apache / traffic_control | 6.0.1-rc0 | 6.0.1-rc0.x |
| apache / traffic_control | 6.0.0 | 6.0.1 |
| apache / traffic_control | 5.1.4-rc0 | 5.1.4-rc0.x |
| apache / traffic_control | 5.1.0 | 5.1.4 |