← volver
CVE-2022-23942

Apache Doris hardcoded cryptography initialization

EPSS 3.1%CWE-798
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →