Описание
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.0 (исключая)
cpe:2.3:a:apache:doris:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.01383
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-798
CWE-798
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 4 года назад
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
EPSS
Процентиль: 80%
0.01383
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-798
CWE-798