Emmanuel Lécharny created DIRAPI-482:
----------------------------------------
Summary: Schema-aware LDIF parse silently drops attributes that
fail validation
Key: DIRAPI-482
URL: https://issues.apache.org/jira/browse/DIRAPI-482
Project: Directory Client API
Issue Type: Bug
Affects Versions: 2.1.8
Reporter: Emmanuel Lécharny
Fix For: 2.1.9
A change-review pipeline validates uploaded *LDIF* with a plain _LdifReader_
(attribute visible, reviewer approves), then deployment re-parses with a
schema-aware _LdifReader_ against a strict _SchemaManager_.
The attacker crafted the value so _addAttribute_ throws there, so the deployed
entry silently lacks the restrictive attribute the reviewer approved.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]