CVE-2018-1337

CRITICAL

Apache Directory Ldap API < 1.0.2 - Information Disclosure

Title source: rule

Description

In Apache Directory LDAP API before 1.0.2, a bug in the way the SSL Filter was setup made it possible for another thread to use the connection before the TLS layer has been established, if the connection has already been used and put back in a pool of connections, leading to leaking any information contained in this request (including the credentials when sending a BIND request).

Exploits (2)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2018-1337-directory-ldap-api-vulnerable
nomisec STUB
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2018-1337-directory-ldap-api-vulnerable

Scores

CVSS v3 9.8
EPSS 0.0266
EPSS Percentile 85.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (2)
apache/directory_ldap_api < 1.0.2
org.apache.directory.api/apache-ldap-api 0 - 1.0.2Maven
Published Jul 10, 2018
Tracked Since Feb 18, 2026