ZeroHour

CVE-2019-10224

CVSS 3.1
4.6 medium
EPSS
<1%p33
Published
()
Modified
Description

A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

Vendors
fedoraproject
Products
389 directory server
Weakness
CWE-522, CWE-200
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.