[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2023-08-23 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17758153#comment-17758153 ] Richard N. Hillegas commented on DERBY-7147: This issue has been assigned CVE

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-08 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17645003#comment-17645003 ] Richard N. Hillegas commented on DERBY-7147: I'm done with the work I plan to

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-07 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17644419#comment-17644419 ] ASF subversion and git services commented on DERBY-7147: Commit 1

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-07 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17644418#comment-17644418 ] Richard N. Hillegas commented on DERBY-7147: Attaching derby-7147-04-aa-point

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-07 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17644408#comment-17644408 ] ASF subversion and git services commented on DERBY-7147: Commit 1

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-06 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17643970#comment-17643970 ] ASF subversion and git services commented on DERBY-7147: Commit 1

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-04 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17643043#comment-17643043 ] Richard N. Hillegas commented on DERBY-7147: I think that the LDAP provider s

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17642921#comment-17642921 ] Bryan Pendleton commented on DERBY-7147: Perhaps we can proceed with what we have

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17642879#comment-17642879 ] Bryan Pendleton commented on DERBY-7147: Actually, I think I did my ldaps test in

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17642863#comment-17642863 ] Richard N. Hillegas commented on DERBY-7147: Thanks for that feedback, Bryan.

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-12-03 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17642851#comment-17642851 ] Bryan Pendleton commented on DERBY-7147: Those documentation updates seem like go

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-29 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17640966#comment-17640966 ] Richard N. Hillegas commented on DERBY-7147: Attaching derby-7147-03-aa-updat

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-29 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17640774#comment-17640774 ] Richard N. Hillegas commented on DERBY-7147: I think that we need to update t

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-29 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17640706#comment-17640706 ] Bryan Pendleton commented on DERBY-7147: Fine with me to make just a 10.16.2 rele

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-28 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17640294#comment-17640294 ] Richard N. Hillegas commented on DERBY-7147: At a minimum, I think that we ne

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-28 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17640286#comment-17640286 ] ASF subversion and git services commented on DERBY-7147: Commit 1

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-28 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17640283#comment-17640283 ] ASF subversion and git services commented on DERBY-7147: Commit 1

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-27 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17639730#comment-17639730 ] ASF subversion and git services commented on DERBY-7147: Commit 1

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17639555#comment-17639555 ] ASF subversion and git services commented on DERBY-7147: Commit 1

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17639554#comment-17639554 ] Richard N. Hillegas commented on DERBY-7147: Thanks for testing the patch, Br

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17639540#comment-17639540 ] Bryan Pendleton commented on DERBY-7147: Rick, a possible difference between your

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17639539#comment-17639539 ] Bryan Pendleton commented on DERBY-7147: Anyway, if it wasn't clear from the abov

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17639538#comment-17639538 ] Bryan Pendleton commented on DERBY-7147: Yay! I've successfully run LDAPAuthentic

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17639510#comment-17639510 ] Richard N. Hillegas commented on DERBY-7147: The ant command works for me aga

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-26 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17639509#comment-17639509 ] Bryan Pendleton commented on DERBY-7147: Hi Rick, sorry for these stupid question

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-23 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17637898#comment-17637898 ] Richard N. Hillegas commented on DERBY-7147: Attaching derby-7147-02-ab-escap

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-23 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17637772#comment-17637772 ] Bryan Pendleton commented on DERBY-7147: Rick, my fairly casual read of [RFC 225

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17637475#comment-17637475 ] Bryan Pendleton commented on DERBY-7147: Uh-oh! Reverting your patch makes the pr

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17637473#comment-17637473 ] Bryan Pendleton commented on DERBY-7147: That's a good point! I do have your patc

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17637466#comment-17637466 ] Richard N. Hillegas commented on DERBY-7147: Thanks for slogging through this

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17637439#comment-17637439 ] Bryan Pendleton commented on DERBY-7147: My attempts to connect to the ApacheDS s

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-22 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17637437#comment-17637437 ] Bryan Pendleton commented on DERBY-7147: I've been trying to verify that Derby ca

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636981#comment-17636981 ] Bryan Pendleton commented on DERBY-7147: Here's a tiny little bit of instructions

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636980#comment-17636980 ] Bryan Pendleton commented on DERBY-7147: Archive.org finds that ancient broken li

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636844#comment-17636844 ] Richard N. Hillegas commented on DERBY-7147: Attaching derby-7147-02-aa-escap

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636778#comment-17636778 ] ASF subversion and git services commented on DERBY-7147: Commit 1

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-21 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636777#comment-17636777 ] Richard N. Hillegas commented on DERBY-7147: Attaching derby-7147-01-aa-refor

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-20 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636344#comment-17636344 ] Bryan Pendleton commented on DERBY-7147: I can test on Linux, and possibly (if we

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-20 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636303#comment-17636303 ] Richard N. Hillegas commented on DERBY-7147: If you can figure out how to run

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-19 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636217#comment-17636217 ] Bryan Pendleton commented on DERBY-7147: That seems like it could be a useful ste

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-19 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636207#comment-17636207 ] Richard N. Hillegas commented on DERBY-7147: There are other dead links in th

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-19 Thread Bryan Pendleton (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17636172#comment-17636172 ] Bryan Pendleton commented on DERBY-7147: Can we adapt our LDAP sample instruction

[jira] [Commented] (DERBY-7147) LDAP injection vulnerability in LDAPAuthenticationImpl

2022-11-07 Thread Richard N. Hillegas (Jira)
[ https://issues.apache.org/jira/browse/DERBY-7147?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17629837#comment-17629837 ] Richard N. Hillegas commented on DERBY-7147: As a first step toward fixing th