漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
StartTLS and SASL confidentiality protection bypass
Vulnerability Description
While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache Directory Studio version 2.0.0.v20210213-M16 and prior versions.
CVSS Information
N/A
Vulnerability Type
敏感数据加密缺失
Vulnerability Title
Apache Directory Studio 安全漏洞
Vulnerability Description
Apache Directory Studio是美国阿帕奇(Apache)基金会的一个完整的目录工具平台,旨在与任何 LDAP 服务器一起使用,但它是专门为与 ApacheDS 一起使用而设计的。 Apache Directory Studio 版本 2.0.0.v20210213-M16 和之前的版本存在安全漏洞,该漏洞源于在使用任何 SASL 身份验证机制(DIGEST-MD5、GSSAPI)时未应用配置的 StartTLS 加密。
CVSS Information
N/A
Vulnerability Type
N/A