Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14824

Опубликовано: 08 нояб. 2019
Источник: nvd
CVSS3: 6.5
CVSS3: 6.5
CVSS2: 3.5
EPSS Низкий

Описание

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fedoraproject:389_directory_server:-:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00204
Низкий

6.5 Medium

CVSS3

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-732
CWE-732

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
redhat
больше 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
debian
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could u ...

CVSS3: 6.5
github
больше 3 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

oracle-oval
около 6 лет назад

ELSA-2019-3981: 389-ds-base security and bug fix update (IMPORTANT)

EPSS

Процентиль: 42%
0.00204
Низкий

6.5 Medium

CVSS3

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-732
CWE-732