Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.
"https://github.com/pypa/advisory-database/blob/main/vulns/pydoris/PYSEC-2022-43150.yaml"