A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2004-1 | 389-ds-base security update |
![]() |
DLA-3399-1 | 389-ds-base security update |
![]() |
EUVD-2019-5952 | A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-13T16:27:22.527Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14824

No data.

Status : Modified
Published: 2019-11-08T15:15:11.563
Modified: 2024-11-21T04:27:26.460
Link: CVE-2019-14824


No data.