[
https://issues.apache.org/jira/browse/CASSANDRA-18723?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17752079#comment-17752079
]
Ekaterina Dimitrova edited comment on CASSANDRA-18723 at 8/8/23 2:56 PM:
-------------------------------------------------------------------------
{quote}Can confirm OWASP passes with that patch.
{quote}
I am +1 to close the ticket in favor of CASSANDRA-18729 (assuming I did not see
anyone complaining during review about the pointed change, and it will be
committed soon)
was (Author: e.dimitrova):
{quote}Can confirm OWASP passes with that patch.
{quote}
I am +1 to close the ticket in favor of CASSANDRA-18729 (assuming I did not see
anyone complaining during review about the pointed change)
> bcprov-jdk15on-1.70.jar vulnerability: CVE-2023-33201
> -----------------------------------------------------
>
> Key: CASSANDRA-18723
> URL: https://issues.apache.org/jira/browse/CASSANDRA-18723
> Project: Cassandra
> Issue Type: Bug
> Components: Dependencies
> Reporter: Brandon Williams
> Assignee: Brandon Williams
> Priority: Normal
> Fix For: 5.x
>
>
> https://nvd.nist.gov/vuln/detail/CVE-2023-33201
> {quote}
> Bouncy Castle For Java before 1.74 is affected by an LDAP injection
> vulnerability. The vulnerability only affects applications that use an LDAP
> CertStore from Bouncy Castle to validate X.509 certificates. During the
> certificate validation process, Bouncy Castle inserts the certificate's
> Subject Name into an LDAP search filter without any escaping, which leads to
> an LDAP injection vulnerability.
> {quote}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]