You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I am interested in upgrading Apache Directory to remediate a few CVEs and would appreciate feedback on my approach before I start
Context
The embedded Apache Directory Server (2.0.0.AM26) currently pulls in multiple CVEs. Moving to 2.0.0.AM27 would require introducing Apache Kerby.
Integration Test Base – testsuite/integration-arquillian/tests/base
Model Test – testsuite/model
Proposed approach
Upgrade Apache Directory Server and introduce Apache Kerby
Fix Keytab generation by adapting KerberosKeytabCreator to Apache Kerby APIs
Set up / adjust the Kerberos embedded server
Fix test any test case failures
Does this approach look correct to you?
Also, are there any guidelines or expectations for testing util/embedded-ldap-server that I should follow while making these changes?
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi Team
I am interested in upgrading Apache Directory to remediate a few CVEs and would appreciate feedback on my approach before I start
Context
The embedded Apache Directory Server (2.0.0.AM26) currently pulls in multiple CVEs. Moving to 2.0.0.AM27 would require introducing Apache Kerby.
Relevant CVEs
CVE-2015-6420
CVE-2015-7501
CVE-2020-15522
CVE-2021-41973
CVE-2023-33201
CVE-2023-33202
CVE-2024-29857
CVE-2024-52046
CVE-2024-30171
Vulnerable dependencies from Apache Directory Server
commons-collections:commons-collections
org.apache.mina:mina-core
org.bouncycastle:bcprov-jdk15on
Keycloak Modules impacted
Proposed approach
Does this approach look correct to you?
Also, are there any guidelines or expectations for testing util/embedded-ldap-server that I should follow while making these changes?
Thanks in advance!
Beta Was this translation helpful? Give feedback.
All reactions