[MAVEN:GHSA-4X25-F45X-GRV5] Missing encryption in Apache Directory Studio

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.

Package Affected Version
pkg:maven/org.apache.directory.studio/org.apache.directory.studio.parent <= 2.0.0.v20210213-M16
ID
MAVEN:GHSA-4X25-F45X-GRV5
Severity
high
URL
https://github.com/advisories/GHSA-4x25-f45x-grv5
Published
2021-08-09T20:40:53
(3 years ago)
Modified
2023-01-29T05:07:50
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.directory.studio/org.apache.directory.studio.parent org.apache.directory.studio org.apache.directory.studio.parent <= 2.0.0.v20210213-M16
Fixed pkg:maven/org.apache.directory.studio/org.apache.directory.studio.parent org.apache.directory.studio org.apache.directory.studio.parent = 2.0.0.v20210717-M17
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...