Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
Workaround:
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://lists.apache.org/thread/com2dyzp3bn2rdrotry90q2zzord4tvt | mailing list vendor advisory |
http://www.openwall.com/lists/oss-security/2022/04/26/2 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2022/04/26/3 | third party advisory mailing list |