GHSA-rcjc-c4pj-xxrp
CRITICALCVE-2022-46337A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow the attacker to execute malware which was visible to and executable by the account which booted the Derby server. In LDAP-protected databases whi
- Affected
- >= 10.1.1.0, < 10.14.3, >= 10.17.0.0, < 10.17.1.0, >= 10.15.0.0, < 10.15.2.1, >= 10.16.0.0, < 10.16.1.2
- Fixed in
- 10.14.3
- Weakness
- CWE-74
- Published
- 2023-11-20
- Source
- github