A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
2019-11-08T15:15:11.563
2024-11-21T04:27:26.460
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fedoraproject | 389_directory_server | - | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |