Description
Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.
Remediation
References
https://lists.apache.org/thread/3bxf7rbf4zh95r78jtgth6gwhr5fyl2j
Related Vulnerabilities
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-api
CVE-2022-43432 Vulnerability in maven package org.jenkins-ci.plugins:xframium
CVE-2020-2300 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2023-26464 Vulnerability in maven package log4j:log4j
CVE-2021-25641 Vulnerability in maven package org.apache.dubbo:dubbo