peter bassill · operator
$ cve CVE-2018-1337 JSON

CVE-2018-1337

9.8
CRITICAL · CVSS 3.0 · EPSS 5.2% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.15% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploitnone known
Published2018-07-10
Last modified2026-06-17

Affected (1)

VendorProduct
apachedirectory ldap api

References

→ the Explorer  ·  watch your stack  ·  NVD