QID 981713
QID 981713: Java (maven) Security Update for org.apache.directory.studio:org.apache.directory.studio.parent (GHSA-4x25-f45x-grv5)
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4x25-f45x-grv5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4x25-f45x-grv5 -
github.com/advisories/GHSA-4x25-f45x-grv5
CVEs related to QID 981713
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4x25-f45x-grv5 | org.apache.directory.studio:org.apache.directory.studio.parent |
|