Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-349x-pch6-942w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

EPSS

Процентиль: 16%
0.00052
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-200
CWE-522

Связанные уязвимости

CVSS3: 4.6
ubuntu
около 6 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

CVSS3: 4.3
redhat
около 7 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

CVSS3: 4.6
nvd
около 6 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

CVSS3: 4.6
debian
около 6 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. ...

oracle-oval
около 6 лет назад

ELSA-2019-3401: 389-ds:1.4 security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 16%
0.00052
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-200
CWE-522