Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11770

Опубликовано: 31 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

Отчет

A Moderate impact information disclosure flaw was found in 389 Directory Server. An unauthenticated remote attacker can exploit an LDAP filter injection vulnerability in the CleanAllRUV status-check extended operation. Red Hat products with nsslapd-allow-anonymous-access enabled by default are particularly susceptible.

Меры по смягчению последствий

Set nsslapd-allow-anonymous-access to rootdse or off. Restrict LDAP ports to trusted networks. Monitor for extop OID 2.16.840.1.113730.3.6.8. Use strong replication manager passwords.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 12redhat-ds:12/389-ds-baseAffected
Red Hat Directory Server 13389-ds-baseAffected
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 7389-ds-baseAffected
Red Hat Enterprise Linux 8389-ds-baseAffected
Red Hat Directory Server 11.9 for RHEL 8redhat-dsFixedRHSA-2026:5553217.08.2026
Red Hat Enterprise Linux 10389-ds-baseFixedRHSA-2026:5542417.08.2026
Red Hat Enterprise Linux 10.0 Extended Update Support389-ds-baseFixedRHSA-2026:5542517.08.2026
Red Hat Enterprise Linux 9389-ds-baseFixedRHSA-2026:5542317.08.2026
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions389-ds-baseFixedRHSA-2026:5542117.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-90
https://bugzilla.redhat.com/show_bug.cgi?id=2484802389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check

EPSS

Процентиль: 43%
0.00545
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
19 дней назад

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
nvd
19 дней назад

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

CVSS3: 7.5
debian
19 дней назад

A flaw was found in 389 Directory Server. An unauthenticated remote at ...

CVSS3: 7.5
github
19 дней назад

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.

EPSS

Процентиль: 43%
0.00545
Низкий

7.5 High

CVSS3