CyberRota Analysis
AI-GeneratedThe Apache Directory LDAP API versions prior to 2.1.9 are vulnerable to a cleartext transmission issue, where sensitive information can be exposed during a StartTLS operation initiated after a Search request, before the TLS handshake is finalized. This vulnerability could lead to unauthorized access to sensitive data. Organizations using affected versions should prioritize upgrading to 2.1.9 to mitigate this risk.
Original NVD Description
Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to upgrade to version 2.1.9, which fixes the issue.