Emmanuel Lécharny created DIRAPI-482:
----------------------------------------

             Summary: Schema-aware LDIF parse silently drops attributes that 
fail validation
                 Key: DIRAPI-482
                 URL: https://issues.apache.org/jira/browse/DIRAPI-482
             Project: Directory Client API
          Issue Type: Bug
    Affects Versions: 2.1.8
            Reporter: Emmanuel Lécharny
             Fix For: 2.1.9


A change-review pipeline validates uploaded *LDIF* with a plain _LdifReader_ 
(attribute visible, reviewer approves), then deployment re-parses with a 
schema-aware _LdifReader_ against a strict _SchemaManager_.
The attacker crafted the value so _addAttribute_ throws there, so the deployed 
entry silently lacks the restrictive attribute the reviewer approved.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to