First published: Tue Apr 26 2022(Updated: )
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Doris | <1.0.0 | |
pip/pydoris | <1.0.0 | 1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23942 has a medium severity rating due to potential information disclosure risks.
To mitigate CVE-2022-23942, upgrade Apache Doris to version 1.0.0 or later.
CVE-2022-23942 is a vulnerability involving hardcoded keys which affects the security of LDAP password initialization.
All versions of Apache Doris prior to 1.0.0 are affected by CVE-2022-23942.
There is no specific workaround for CVE-2022-23942 other than upgrading to the secure version.