Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3652

Опубликовано: 29 июн. 2021
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 9389-ds-baseNot affected
Red Hat Directory Server 11.4 for RHEL 8redhat-dsFixedRHSA-2021:395525.10.2021
Red Hat Enterprise Linux 7389-ds-baseFixedRHSA-2021:380712.10.2021
Red Hat Enterprise Linux 8389-dsFixedRHSA-2021:307910.08.2021
Red Hat Enterprise Linux 8.2 Extended Update Support389-dsFixedRHSA-2021:390619.10.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1982782389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.

CVSS3: 6.5
nvd
почти 4 года назад

A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.

CVSS3: 6.5
debian
почти 4 года назад

A flaw was found in 389-ds-base. If an asterisk is imported as passwor ...

suse-cvrf
больше 4 лет назад

Security update for 389-ds

suse-cvrf
больше 4 лет назад

Security update for 389-ds

6.5 Medium

CVSS3

Уязвимость CVE-2021-3652