ZeroHour

CVE-2020-35518

CVSS 3.1
5.3 medium
EPSS
2%p73
Published
()
Modified
Description

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.

Vendors
redhat
Products
389 directory server, directory server, enterprise linux
Weakness
CWE-200, CWE-203
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.