[ 
https://issues.apache.org/jira/browse/GEODE-10591?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099814#comment-18099814
 ] 

ASF subversion and git services commented on GEODE-10591:
---------------------------------------------------------

Commit c679a7e2f590deb29ee9413f19514f769b735adf in geode's branch 
refs/heads/develop from Jinwoo Hwang
[ https://gitbox.apache.org/repos/asf?p=geode.git;h=c679a7e2f5 ]

[GEODE-10591] Remediation of CVE-2026-49268 (#8017)

* Remediation of CVE-2026-49268

* CI build failure

> Remediation of CVE-2026-49268
> -----------------------------
>
>                 Key: GEODE-10591
>                 URL: https://issues.apache.org/jira/browse/GEODE-10591
>             Project: Geode
>          Issue Type: Improvement
>            Reporter: Jinwoo Hwang
>            Assignee: Jinwoo Hwang
>            Priority: Major
>
> Affected versions of this package are vulnerable to LDAP Injection in the 
> `DefaultLdapRealm` class. An attacker can bypass authentication or 
> impersonate other users by injecting LDAP special characters into the 
> Distinguished Name (DN) construction during LDAP bind authentication.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to