A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2019:3981 | Vendor Advisory |
https://access.redhat.com/errata/RHSA-2020:0464 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14824 | Issue Tracking Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2019/11/msg00036.html | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html |
Configurations
History
No history.
Information
Published : 2019-11-08 15:15
Updated : 2023-04-24 09:15
NVD link : CVE-2019-14824
Mitre link : CVE-2019-14824
CVE.ORG link : CVE-2019-14824
JSON object : View
Products Affected
redhat
- enterprise_linux
debian
- debian_linux
fedoraproject
- 389_directory_server
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource