PT-2022-10487 · Apache · Apache Gobblin

Simon Gerst

·

Published

2022-02-04

·

Updated

2022-02-09

·

CVE-2021-36152

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Gobblin versions <= 0.15.0
Description The issue is related to Apache Gobblin trusting all certificates used for LDAP connections in Gobblin-as-a-Service. This allows for potential security risks.
Recommendations For Apache Gobblin versions <= 0.15.0, update to version 0.16.0 to address the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-36152
GHSA-Q5RX-8C2H-5Q7J

Affected Products

Apache Gobblin