Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14824

Опубликовано: 08 нояб. 2019
Источник: debian
EPSS Низкий

Описание

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
389-ds-basefixed1.4.2.4-1package
389-ds-baseno-dsastretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1747448

  • https://pagure.io/freeipa/issue/8050

  • https://github.com/389ds/389-ds-base/issues/3771

EPSS

Процентиль: 67%
0.01311
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
redhat
почти 7 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
nvd
больше 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
github
около 4 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

oracle-oval
больше 6 лет назад

ELSA-2019-3981: 389-ds-base security and bug fix update (IMPORTANT)

EPSS

Процентиль: 67%
0.01311
Низкий