Логотип exploitDog
bind:CVE-2019-14870
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-14870

Количество 12

Количество 12

ubuntu логотип

CVE-2019-14870

около 6 лет назад

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2019-14870

около 6 лет назад

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-14870

около 6 лет назад

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-14870

около 6 лет назад

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11 ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-6q5r-wx7g-rq28

больше 3 лет назад

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2021-01743

около 6 лет назад

Уязвимость пакета программ сетевого взаимодействия Samba, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS3: 5.4
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2700-1

около 6 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:3319-1

около 6 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:3318-1

около 6 лет назад

Security update for samba

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2023:0020-1

около 3 лет назад

Security update for libheimdal

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2023:0019-1

около 3 лет назад

Security update for libheimdal

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2673-1

больше 5 лет назад

Security update for samba

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-14870

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

CVSS3: 5.4
5%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-14870

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

CVSS3: 5.4
5%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-14870

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

CVSS3: 5.4
5%
Низкий
около 6 лет назад
debian логотип
CVE-2019-14870

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11 ...

CVSS3: 5.4
5%
Низкий
около 6 лет назад
github логотип
GHSA-6q5r-wx7g-rq28

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authentication, by forcing all tickets for these clients to be non-forwardable. In AD this is implemented by a user attribute delegation_not_allowed (aka not-delegated), which translates to disallow-forwardable. However the Samba AD DC does not do that for S4U2Self and does set the forwardable flag even if the impersonated client has the not-delegated flag set.

CVSS3: 5.4
5%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-01743

Уязвимость пакета программ сетевого взаимодействия Samba, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS3: 5.4
5%
Низкий
около 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2700-1

Security update for samba

около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:3319-1

Security update for samba

около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:3318-1

Security update for samba

около 6 лет назад
suse-cvrf логотип
openSUSE-SU-2023:0020-1

Security update for libheimdal

около 3 лет назад
suse-cvrf логотип
openSUSE-SU-2023:0019-1

Security update for libheimdal

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2020:2673-1

Security update for samba

больше 5 лет назад

Уязвимостей на страницу