Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14824

Опубликовано: 08 нояб. 2019
Источник: debian

Описание

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
389-ds-basefixed1.4.2.4-1package
389-ds-baseno-dsastretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1747448

  • https://pagure.io/freeipa/issue/8050

  • https://github.com/389ds/389-ds-base/issues/3771

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
redhat
больше 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
nvd
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
github
больше 3 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

oracle-oval
около 6 лет назад

ELSA-2019-3981: 389-ds-base security and bug fix update (IMPORTANT)