CVE-2018-1337

CVSS v3.0 9.8 (Critical)
98% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 1.30 % (86th)
1.30% Progress
Affected Products 1
Advisories 1

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2018-07-10 13:29:00
(6 years ago)
Updated Date
2023-11-07 02:55:59
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Directory Ldap Api prior 1.0.2 version cpe:2.3:a:apache:directory_ldap_api < 1.0.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...