Описание
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 1.3.7.10-1ubuntu1 |
| cosmic | not-affected | 1.3.7.10-1ubuntu1 |
| devel | not-affected | 1.3.7.10-1ubuntu1 |
| disco | not-affected | 1.3.7.10-1ubuntu1 |
| eoan | not-affected | 1.3.7.10-1ubuntu1 |
| esm-apps/bionic | not-affected | 1.3.7.10-1ubuntu1 |
| esm-apps/focal | not-affected | 1.3.7.10-1ubuntu1 |
| esm-apps/jammy | not-affected | 1.3.7.10-1ubuntu1 |
| esm-apps/xenial | not-affected | code not present |
Показывать по
Ссылки на источники
4.3 Medium
CVSS2
8.1 High
CVSS3
Связанные уязвимости
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0. ...
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.
Уязвимость службы каталогов уровня предприятия 389 Directory Server, связанная с неправильной аутентификацией, позволяющая нарушителю получить доступ к конфиденциальным данным
4.3 Medium
CVSS2
8.1 High
CVSS3