Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-349x-pch6-942w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

EPSS

Процентиль: 32%
0.00396
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-200
CWE-522

Связанные уязвимости

CVSS3: 4.6
ubuntu
больше 6 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

CVSS3: 4.3
redhat
больше 7 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

CVSS3: 4.6
nvd
больше 6 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

CVSS3: 4.6
debian
больше 6 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. ...

oracle-oval
больше 6 лет назад

ELSA-2019-3401: 389-ds:1.4 security, bug fix, and enhancement update (IMPORTANT)

EPSS

Процентиль: 32%
0.00396
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-200
CWE-522