QID 981128

QID 981128: Java (maven) Security Update for org.apache.directory.api:apache-ldap-api (GHSA-cfw5-v7cw-69cw)

In Apache LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-cfw5-v7cw-69cw for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981128

    Software Advisories
    Advisory ID Software Component Link
    GHSA-cfw5-v7cw-69cw org.apache.directory.api:apache-ldap-api URL Logo github.com/advisories/GHSA-cfw5-v7cw-69cw