CVE-2022-23942
published 2022-04-26CVE-2022-23942: Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.32%
87.3th percentile
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | doris | < 1.0.0 | 1.0.0 |
| apache_software_foundation | apache_doris | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Doris hardcoded key and IV
osv·2022-04-27
CVE-2022-23942 [HIGH] Apache Doris hardcoded key and IV
Apache Doris hardcoded key and IV
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
GHSA
Apache Doris hardcoded key and IV
ghsa·2022-04-27
CVE-2022-23942 [HIGH] CWE-798 Apache Doris hardcoded key and IV
Apache Doris hardcoded key and IV
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
OSV
CVE-2022-23942: Apache Doris, prior to 1
osv·2022-04-26
CVE-2022-23942 CVE-2022-23942: Apache Doris, prior to 1
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/04/26/2http://www.openwall.com/lists/oss-security/2022/04/26/3https://lists.apache.org/thread/com2dyzp3bn2rdrotry90q2zzord4tvthttp://www.openwall.com/lists/oss-security/2022/04/26/2http://www.openwall.com/lists/oss-security/2022/04/26/3https://lists.apache.org/thread/com2dyzp3bn2rdrotry90q2zzord4tvt
2022-04-26
Published