Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19404

Опубликовано: 10 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.

Отчет

A Moderate impact flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an attacker able to reach a supplier's LDAP listener to remove a replica's entry from replication metadata, purge its changelog records, or interrupt an administrator's in-progress cleanup. Red Hat products with nsslapd-allow-anonymous-access enabled by default (the shipped default) allow this without any authentication; when that setting has been restricted, any authenticated account, regardless of privilege level, can still trigger the same behavior, since the affected operations do not perform an authorization check of their own.

Меры по смягчению последствий

Set nsslapd-allow-anonymous-access to rootdse or off as an interim mitigation. Note this only blocks exploitation by fully unauthenticated (unbound) clients; any connection that has completed a successful bind with any DN, including a low-privileged account, still reaches the vulnerable handlers with no further authorization check. Restrict replication LDAP ports to trusted networks as defense in depth pending a code fix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Directory Server 11389-ds-baseFix deferred
Red Hat Directory Server 12389-ds-baseFix deferred
Red Hat Directory Server 13389-ds-baseFix deferred
Red Hat Enterprise Linux 10389-ds-baseFix deferred
Red Hat Enterprise Linux 6389-ds-baseOut of support scope
Red Hat Enterprise Linux 7389-ds-baseFix deferred
Red Hat Enterprise Linux 8389-ds-baseFix deferred
Red Hat Enterprise Linux 9389-ds-baseFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2513036389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abort CleanAllRUV replication maintenance

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
7 дней назад

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.

CVSS3: 6.5
nvd
7 дней назад

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.

CVSS3: 6.5
debian
7 дней назад

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort Cl ...

CVSS3: 6.5
github
7 дней назад

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.

6.5 Medium

CVSS3