CVE-2020-1958: Information Exposure
(updated )
When LDAP authentication is enabled in Apache Druid, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch
filter barrier that determines if a valid LDAP user is allowed to authenticate with Druid.
References
Detect and mitigate CVE-2020-1958 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →