OWASP / OWASP/ASVS

Clarification: V1.2.6 "or that specific security controls... have been implemented"

Open
#3,210 18 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

V1 (prev V5)
Dominant language
HTML
Stars
3.6k
Forks
831
Avg merge
7h 55m
Merged PRs (30d)
4

Description

Verify that the application protects against LDAP injection vulnerabilities, or that specific security controls to prevent LDAP injection have been implemented.

  • Difficult to understand/define action on below the statement

“or that specific security controls... have been implemented.”

Which controls? Escaping? Input validation? Escaping? Parameterized APIs?

  • “application protects against LDAP injection vulnerabilities” – is too broad and lacks measurable criteria. It should be described slightly like mentioning the LDAP escaping RFC rules like 4515 or other important implementations.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the V1.2.6 statement quoted in the issue and review the 18-comment discussion about what “specific security controls” and measurable LDAP injection protection should mean. Check the cited RFC 4515 context and the proposed alternatives; done means reaching agreed, precise wording for the verification requirement.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.