Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh8x-vwrj-w4f2

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise 2018.1.4, 2017.3.10, and 2016.4.15. It scored an 8.5 CVSS score.

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise 2018.1.4, 2017.3.10, and 2016.4.15. It scored an 8.5 CVSS score.

EPSS

Процентиль: 36%
0.00154
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise 2018.1.4, 2017.3.10, and 2016.4.15. It scored an 8.5 CVSS score.

CVSS3: 9.8
nvd
больше 7 лет назад

When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, 2017.3.9, and 2016.4.14, and is fixed in Puppet Enterprise 2018.1.4, 2017.3.10, and 2016.4.15. It scored an 8.5 CVSS score.

CVSS3: 9.8
debian
больше 7 лет назад

When users are configured to use startTLS with RBAC LDAP, at login tim ...

EPSS

Процентиль: 36%
0.00154
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-319