Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wxh-5wv6-x378

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

EPSS

Процентиль: 42%
0.00204
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
redhat
больше 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
nvd
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
debian
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could u ...

oracle-oval
около 6 лет назад

ELSA-2019-3981: 389-ds-base security and bug fix update (IMPORTANT)

EPSS

Процентиль: 42%
0.00204
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-732