CVE-2018-1337

unknown
Published 2018-11-09 · Modified 2024-04-19
CVSS v3
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
not yet in upstream
VIR risk

Description

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2018-1337 NameCVE-2018-1337 DescriptionIn Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials…

CVE-2018-1337

NameCVE-2018-1337
DescriptionIn Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache-directory-api (PTS)bullseye1.0.0-2vulnerable
bookworm2.1.2-1fixed
forky, sid, trixie2.1.2-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache-directory-apisource(unstable)2.1.2-1

Notes

https://lists.apache.org/thread/lrfz3057jbz6ssyg7scmcrpx46qopcm5

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://lists.apache.org/thread/lrfz3057jbz6ssyg7scmcrpx46qopcm5

OS impact

debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 2.1.2-1
sid Fixed 2.1.2-1
forky Fixed 2.1.2-1
bullseye Affected
bookworm Fixed 2.1.2-1

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.directory.api:apache-ldap-api<1.0.21.0.2

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.