Логотип exploitDog
bind:CVE-2018-1337
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-1337

Количество 2

Количество 2

nvd логотип

CVE-2018-1337

больше 7 лет назад

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cfw5-v7cw-69cw

около 7 лет назад

Credential leak in org.apache.directory.api:apache-ldap-api

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-1337

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).

CVSS3: 9.8
3%
Низкий
больше 7 лет назад
github логотип
GHSA-cfw5-v7cw-69cw

Credential leak in org.apache.directory.api:apache-ldap-api

CVSS3: 9.8
3%
Низкий
около 7 лет назад

Уязвимостей на страницу