← voltar
CVE-2022-23942

Apache Doris hardcoded cryptography initialization

EPSS 3.1%CWE-798
Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →