PT-2018-11784 · Apache · Apache Directory Ldap Api

Publicado

2018-07-10

·

Atualizado

2020-08-24

·

CVE-2018-1337

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Directory LDAP API versions prior to 1.0.2
Description A bug in the setup of the SSL Filter allows another thread to use a connection before the TLS layer is established, potentially leaking information, including credentials sent in a BIND request.
Recommendations For versions prior to 1.0.2, update to version 1.0.2 or later to resolve the issue. As a temporary workaround, consider disabling connection pooling to minimize the risk of exploitation. Restrict access to sensitive operations, such as BIND requests, until the issue is resolved.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1337
GHSA-CFW5-V7CW-69CW

Produtos afetados

Apache Directory Ldap Api