Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2022-02-07T23:07:32Z",
"nvd_published_at": "2022-02-04T23:15:00Z",
"severity": "CRITICAL"
}