Описание
Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-apps-legacy/xenial | released | 2.2.5-1ubuntu0.2+esm3 |
| esm-apps/bionic | released | 2.2.6-1ubuntu0.18.04.2+esm3 |
| esm-apps/focal | released | 3.1.12~ds-4ubuntu0.20.04.4+esm1 |
| esm-apps/jammy | released | 3.1.12~ds-9ubuntu0.22.04.4+esm1 |
| esm-apps/noble | released | 3.1.18~ds-1ubuntu0.1~esm2 |
| esm-apps/resolute | released | 4.2.3~ds-2.1ubuntu0.1 |
| esm-infra-legacy/trusty | released | 2.2.2-1ubuntu2.2+esm3 |
| jammy | needed | |
| noble | needed |
Показывать по
10
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
nvd
3 месяца назад
Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.
CVSS3: 7.5
debian
3 месяца назад
Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into l ...
CVSS3: 7.5
github
3 месяца назад
Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.
7.5 High
CVSS3