Atlassian uses cookies to improve your browsing experience, perform analytics and research, and conduct advertising. Accept all cookies to indicate that you agree to our use of cookies on your device. Atlassian cookies and tracking notice, (opens new window)
When authenticating using ldap, a simple bind is used. This exposes the admin dn (account used to search ldap), and users username and password.
I was able to confirm this while running wireshark on the ldap server that openfire authenticates with.
This can be mitigated by using ldaps and starttls.