Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cmm2-4q45-jpgh

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.8

Описание

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

EPSS

Процентиль: 60%
0.00393
Низкий

3.8 Low

CVSS3

Дефекты

CWE-90

Связанные уязвимости

CVSS3: 3.8
ubuntu
больше 7 лет назад

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

CVSS3: 3.8
redhat
больше 7 лет назад

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

CVSS3: 3.8
nvd
больше 7 лет назад

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

CVSS3: 3.8
debian
больше 7 лет назад

MIT krb5 1.6 or later allows an authenticated kadmin with permission t ...

suse-cvrf
больше 6 лет назад

Security update for krb5

EPSS

Процентиль: 60%
0.00393
Низкий

3.8 Low

CVSS3

Дефекты

CWE-90