DataHub LDAP Ingestion Source TLS Downgrade Vulnerability Allowing MITM Attacks

Vulnerability

A vulnerability in the LDAP ingestion source of DataHub, prior to version 1.3.1.8, allows for man-in-the-middle (MITM) attacks through a TLS downgrade. The issue arises because the LDAP source improperly validates TLS certificates, accepting connections even when validation fails. This flaw enables an attacker to intercept LDAPS credentials by presenting a rogue certificate. The vulnerability is exacerbated by the absence of a configuration option to specify trusted CA certificates, and the hardcoded setting that ignores validation failures.

Impact

Exploitation of this vulnerability could lead to unauthorized interception of LDAPS credentials, allowing an attacker to capture sensitive information transmitted over the LDAP connection.

Remediation

Users should update to DataHub version 1.3.1.8 or later. Additionally, ensure that the DataHub deployment only exposes necessary external services, ideally within a fully internal network between DataHub and the LDAP deployment.

Added: Feb 7, 2026, 12:16 AM
Updated: Feb 7, 2026, 12:16 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
5.9
remediation
7.9
relevance
2.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.