Description
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-23185 | When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database. |
Ubuntu USN |
USN-5231-1 | 389 Directory Server vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T17:02:08.248Z
Reserved: 2020-12-17T00:00:00.000Z
Link: CVE-2020-35518
No data.
Status : Modified
Published: 2021-03-26T17:15:12.280
Modified: 2024-11-21T05:27:28.920
Link: CVE-2020-35518
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN