Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23942.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "1.0.0" } ] } ]