A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14824 | Issue Tracking Vendor Advisory |
https://access.redhat.com/errata/RHSA-2019:3981 | Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2019/11/msg00036.html | Mailing List Third Party Advisory |
https://access.redhat.com/errata/RHSA-2020:0464 | Vendor Advisory |
Information
Published : 2019-11-08 07:15
Updated : 2023-02-12 15:34
NVD link : CVE-2019-14824
Mitre link : CVE-2019-14824
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
debian
- debian_linux
redhat
- enterprise_linux
fedoraproject
- 389_directory_server