Описание
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | krb5 | Will not fix | ||
| Red Hat Enterprise Linux 6 | krb5 | Will not fix | ||
| Red Hat Enterprise Linux 8 | krb5 | Not affected | ||
| Red Hat JBoss Core Services | krb5 | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | krb5 | Will not fix | ||
| Red Hat JBoss Enterprise Web Server 2 | krb5 | Will not fix | ||
| Red Hat Enterprise Linux 7 | krb5 | Fixed | RHSA-2018:3071 | 30.10.2018 |
Показывать по
Дополнительная информация
Статус:
3.8 Low
CVSS3
Связанные уязвимости
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
MIT krb5 1.6 or later allows an authenticated kadmin with permission t ...
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
3.8 Low
CVSS3