[
https://issues.apache.org/jira/browse/GEODE-10591?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099814#comment-18099814
]
ASF subversion and git services commented on GEODE-10591:
---------------------------------------------------------
Commit c679a7e2f590deb29ee9413f19514f769b735adf in geode's branch
refs/heads/develop from Jinwoo Hwang
[ https://gitbox.apache.org/repos/asf?p=geode.git;h=c679a7e2f5 ]
[GEODE-10591] Remediation of CVE-2026-49268 (#8017)
* Remediation of CVE-2026-49268
* CI build failure
> Remediation of CVE-2026-49268
> -----------------------------
>
> Key: GEODE-10591
> URL: https://issues.apache.org/jira/browse/GEODE-10591
> Project: Geode
> Issue Type: Improvement
> Reporter: Jinwoo Hwang
> Assignee: Jinwoo Hwang
> Priority: Major
>
> Affected versions of this package are vulnerable to LDAP Injection in the
> `DefaultLdapRealm` class. An attacker can bypass authentication or
> impersonate other users by injecting LDAP special characters into the
> Distinguished Name (DN) construction during LDAP bind authentication.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)