A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2019-11-08T14:45:46
Updated: 2024-08-05T00:26:39.128Z
Reserved: 2019-08-10T00:00:00
Link: CVE-2019-14824
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-11-08T15:15:11.563
Modified: 2024-11-21T04:27:26.460
Link: CVE-2019-14824
Redhat