[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2024-03-02 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17822865#comment-17822865 ] Richard N. Hillegas commented on DERBY-7147: "It is showing as affected from "10.1.1.0 Up to

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2024-03-01 Thread Mrudula Madiraju (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17822752#comment-17822752 ] Mrudula Madiraju commented on DERBY-7147: - Hi [~rhillegas]   - I guess our scanners report it

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2024-03-01 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17822674#comment-17822674 ] Richard N. Hillegas commented on DERBY-7147: I have verified that the fix has been applied to

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2024-03-01 Thread ajay kumar (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17822505#comment-17822505 ] ajay kumar commented on DERBY-7147: --- [~rhillegas] /[~julienlau] Can you please point me to the source

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2024-01-10 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17805250#comment-17805250 ] Richard N. Hillegas commented on DERBY-7147: No one has volunteered to manage a fix-bearing

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2024-01-10 Thread Laurenceau Julien (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17805057#comment-17805057 ] Laurenceau Julien commented on DERBY-7147: -- I cannot find the derby fixed version 10.16.1.2 on

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2024-01-03 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17802280#comment-17802280 ] Richard N. Hillegas commented on DERBY-7147: I have checked the head of the 10.14 branch and

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2024-01-03 Thread gmlake (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17802150#comment-17802150 ] gmlake commented on DERBY-7147: --- Hello team, I got same problem -  Twistlock tool and Aquasec tool still

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2024-01-03 Thread Mrudula Madiraju (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17802070#comment-17802070 ] Mrudula Madiraju commented on DERBY-7147: - Hello team, This is showing up as a vulnerability in

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2023-12-22 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17799918#comment-17799918 ] Richard N. Hillegas commented on DERBY-7147: I am mystified by the high rating which NVD

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2023-12-22 Thread Susmit Sarkar (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17799793#comment-17799793 ] Susmit Sarkar commented on DERBY-7147: -- We are in JDK 11, when can we expect an official released

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2023-12-21 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17799544#comment-17799544 ] Richard N. Hillegas commented on DERBY-7147: The patch was backported to the 10.16, 10.15,

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2023-12-21 Thread Florian Kolbe (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17799501#comment-17799501 ] Florian Kolbe commented on DERBY-7147: -- {quote} The patch has been backported to the 10.14 branch.

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2023-12-17 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17797959#comment-17797959 ] Richard N. Hillegas commented on DERBY-7147: The patch has been backported to the 10.14

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2023-12-17 Thread Izek Greenfield (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17797952#comment-17797952 ] Izek Greenfield commented on DERBY-7147: [~rhillegas] Is there a version for JDK 1.8 ?  > LDAP

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationSchemeImpl

2023-11-16 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17786963#comment-17786963 ] Richard N. Hillegas commented on DERBY-7147: Attaching LDAPauthenticationVulnerability.pdf,