Dismissed
Permalink
CVE-2026-25644
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
3 packages
- python312Packages.cryptodatahub
- python313Packages.cryptodatahub
- python314Packages.cryptodatahub
- @LeSuisse dismissed
DataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgrade
DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.
References
- https://github.com/datahub-project/datahub/security/advisories/GHSA-j34h-x7qg-4qw5 x_refsource_CONFIRM
- https://github.com/datahub-project/datahub/security/advisories/GHSA-j34h-x7qg-4qw5 x_refsource_CONFIRM
Affected products
datahub
- ==< 1.3.1.8