GHSA-rcjc-c4pj-xxrp

    Dashboard / Vulnerabilities / GHSA-rcjc-c4pj-xxrp

    GHSA-rcjc-c4pj-xxrp

    Published: 20 Nov 2023Last Modified: 10 Sept 2026

    Summary: Apache Derby: LDAP injection vulnerability in authenticator

    Details: A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow the attacker to execute malware which was visible to and executable by the account which booted the Derby server. In LDAP-protected databases which weren't also protected by SQL GRANT/REVOKE authorization, this vulnerability could also let an attacker view and corrupt sensitive data and run sensitive database functions and procedures. Mitigation: Users should upgrade to Java 21 and Derby 10.17.1.0. Alternatively, users who wish to remain on older Java versions should build their own Derby distribution from one of the release families to which the fix was backported: 10.16, 10.15, and 10.14. Those are the releases which correspond, respectively, with Java LTS versions 17, 11, and 8.

    Affected packages

    Package

    Name: org.apache.derby:derby

    Purl: pkg:maven/org.apache.derby/derby

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 10.1.1.0
    Fixed -None

    Affected versions

    10.1.1.0
    10.1.2.1
    10.1.3.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rcjc-c4pj-xxrp | CVE-DB