Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cmm2-4q45-jpgh

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.8

Описание

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

EPSS

Процентиль: 63%
0.00436
Низкий

3.8 Low

CVSS3

Дефекты

CWE-90

Связанные уязвимости

CVSS3: 3.8
ubuntu
почти 8 лет назад

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

CVSS3: 3.8
redhat
почти 8 лет назад

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

CVSS3: 3.8
nvd
почти 8 лет назад

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

CVSS3: 3.8
debian
почти 8 лет назад

MIT krb5 1.6 or later allows an authenticated kadmin with permission t ...

suse-cvrf
почти 7 лет назад

Security update for krb5

EPSS

Процентиль: 63%
0.00436
Низкий

3.8 Low

CVSS3

Дефекты

CWE-90