Security Advisory

CVE-2022-23942

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-04-26 16:05:10
Last updated 2024-08-03 03:59:23
Assigner apache
State PUBLISHED

Description

Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.