First published: Tue Apr 26 2022(Updated: )
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Doris | <1.0.0 | |
pip/pydoris | <1.0.0 | 1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.