LDAPADvisor Android is in early development. There is no stable release yet. Security fixes will target the main branch.
Reports may involve issues such as:
- credential exposure
- LDAP credential leakage
- TLS certificate validation
- insecure LDAP connections
- Android Keystore misuse
- exported Android components
- intent exposure
- sensitive information in logs
- sensitive information in diagnostic reports
- authentication bypass
Do not open a public issue that includes real credentials, private certificates, production Active Directory data, or a working exploit against a live environment.
Private vulnerability reporting channels will be documented here once maintainers publish a preferred contact method.
Until then:
- Avoid publishing sensitive details publicly.
- Sanitize all examples (use
corp.example.comand documentation IP ranges). - Describe impact, affected components, and reproduction steps at a high level when contacting maintainers through a private channel once available.
Contributors and users should assume that directory credentials and internal infrastructure details are highly sensitive. Never commit secrets, signing keys, or production directory exports to this repository.