Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-10224

Опубликовано: 25 нояб. 2019
Источник: ubuntu
Приоритет: low
CVSS2: 2.1
CVSS3: 4.6

Описание

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.4.1.5-1
disco

ignored

end of life
eoan

not-affected

1.4.1.5-1
esm-apps/bionic

needed

esm-apps/focal

not-affected

1.4.1.5-1
esm-apps/jammy

not-affected

1.4.1.5-1
esm-apps/noble

not-affected

1.4.1.5-1
esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

impish

DNE

Показывать по

2.1 Low

CVSS2

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
redhat
около 7 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

CVSS3: 4.6
nvd
около 6 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

CVSS3: 4.6
debian
около 6 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. ...

CVSS3: 4.6
github
больше 3 лет назад

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

oracle-oval
около 6 лет назад

ELSA-2019-3401: 389-ds:1.4 security, bug fix, and enhancement update (IMPORTANT)

2.1 Low

CVSS2

4.6 Medium

CVSS3