Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14824

Опубликовано: 04 нояб. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

Отчет

This vulnerability is rated Important when use in a IdM/IPA environment, where an ACI installed by default allows an authenticated attacker to use this flaw to retrieve the userPassword attribute of any user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 7389-ds-baseFixedRHSA-2019:398126.11.2019
Red Hat Enterprise Linux 8389-dsFixedRHSA-2019:340105.11.2019
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions389-dsFixedRHSA-2020:046410.02.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1747448389-ds-base: Read permission check bypass via the deref plugin

EPSS

Процентиль: 42%
0.00204
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
nvd
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

CVSS3: 6.5
debian
около 6 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could u ...

CVSS3: 6.5
github
больше 3 лет назад

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

oracle-oval
около 6 лет назад

ELSA-2019-3981: 389-ds-base security and bug fix update (IMPORTANT)

EPSS

Процентиль: 42%
0.00204
Низкий

6.5 Medium

CVSS3