Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-35518

Опубликовано: 26 мар. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 5.3

Описание

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

not-affected

2.0.2
esm-apps/bionic

not-affected

code not present
esm-apps/focal

released

1.4.3.6-2ubuntu0.1~esm1
esm-apps/jammy

not-affected

2.0.2
esm-apps/noble

not-affected

2.0.2
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [code not present]]
focal

ignored

end of standard support, was needed
groovy

ignored

end of life

Показывать по

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
около 5 лет назад

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

CVSS3: 5.3
nvd
почти 5 лет назад

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

CVSS3: 5.3
debian
почти 5 лет назад

When binding against a DN during authentication, the reply from 389-ds ...

suse-cvrf
почти 5 лет назад

Security update for 389-ds

suse-cvrf
почти 5 лет назад

Security update for 389-ds

5 Medium

CVSS2

5.3 Medium

CVSS3