-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The JIRA ticket DERBY-7147 explicitly identifies getDNFromUID() in LDAPAuthenticationSchemeImpl as the vulnerable method. The vulnerability stems from improper neutralization of username input when building LDAP queries, matching CWE-74 (Injection). The fix involved adding LDAP search filter escaping, confirming this function's role in the injection vector. The file path is inferred from standard Derby package structures and authentication implementation patterns.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.derby:derby | maven | >= 10.1.1.0, < 10.14.3 | 10.14.3 |
| org.apache.derby:derby | maven | >= 10.15.0.0, < 10.15.2.1 | 10.15.2.1 |
| org.apache.derby:derby | maven | >= 10.16.0.0, < 10.16.1.2 | 10.16.1.2 |
| org.apache.derby:derby | maven | >= 10.17.0.0, < 10.17.1.0 | 10.17.1.0 |
Ongoing coverage of React2Shell