QID 981126
QID 981126: Java (maven) Security Update for org.apache.karaf:apache-karaf (GHSA-chj8-5xgw-wcvj)
Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-chj8-5xgw-wcvj for updates pertaining to this vulnerability.
Vendor References
- GHSA-chj8-5xgw-wcvj -
github.com/advisories/GHSA-chj8-5xgw-wcvj
CVEs related to QID 981126
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-chj8-5xgw-wcvj | org.apache.karaf:apache-karaf |
|