CVE-2015-5349: Apache Directory Studio
High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.
Affected products
- Apache Directory Studio: version 1.0.0 only; version 1.0.1 only; version 1.1.0 only; version 1.2.0 only; version 1.3.0 only; version 1.4.0 only; …
- Apache LDAP Studio: version 0.6.0 only; version 0.7.0 only; version 0.8.0 only; version 0.8.1 only
Published 2016-04-11. Last modified 2026-06-17.