CVE-2019-14824
08.11.2019, 15:15
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fedoraproject | 389_directory_server | - |
| redhat | enterprise_linux | 7.0 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References