Uploaded image for project: 'Jetspeed 2 (Retired)'
  1. Jetspeed 2 (Retired)
  2. JS2-826

Invalid DN values in group/role member attributes result in null pointer dereferences in the BasePrincipalImpl class

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Minor
    • Resolution: Fixed
    • 2.1.3, 2.2.0
    • 2.1.3, 2.2.0
    • Security
    • None

    Description

      If the users belonging to a role are determined by role attributes, so role to user mapping (and not the default, mapping users to roles), then an invalid DN in the role membership attribute will cause a user principal to be created with a NULL name. The reason for that is that the UID attribute (e.g. "CN=") cannot be found in the invalid DN value.

      Attachments

        1. LdapMemberShipDaoImpl.patch
          2 kB
          Dennis Dam

        Activity

          People

            ate Ate Douma
            ddam Dennis Dam
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: