Missing encryption in Apache Directory Studio
High severity
GitHub Reviewed
Published
Aug 9, 2021
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Package
Affected versions
<= 2.0.0.v20210213-M16
Patched versions
2.0.0.v20210717-M17
Description
Published by the National Vulnerability Database
Jul 26, 2021
Reviewed
Aug 2, 2021
Published to the GitHub Advisory Database
Aug 9, 2021
Last updated
Jan 29, 2023
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.
References