ZeroHour

CVE-2019-14824

CVSS 3.1
6.5 medium
EPSS
1%p69
Published
()
Modified
Description

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

Vendors
fedoraprojectredhatdebian
Products
389 directory server, enterprise linux, debian linux
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.