QID 981128
QID 981128: Java (maven) Security Update for org.apache.directory.api:apache-ldap-api (GHSA-cfw5-v7cw-69cw)
In Apache LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cfw5-v7cw-69cw for updates pertaining to this vulnerability.
Vendor References
- GHSA-cfw5-v7cw-69cw -
github.com/advisories/GHSA-cfw5-v7cw-69cw
CVEs related to QID 981128
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cfw5-v7cw-69cw | org.apache.directory.api:apache-ldap-api |
|