Impact
The flaw in 389-ds-base’s Cockpit console constructs an ldapsearch command by directly inserting an LDAP entry’s DN into a shell string without escaping. An LDAP user with the right delegated rights to create or rename entries can forge a DN containing shell metacharacters. When a Cockpit administrator later browses that entry, the command string is executed with root privileges on the directory server host, allowing the attacker to run arbitrary code as root. This effectively hijacks the server’s operating system, compromising confidentiality, integrity, and availability.
Affected Systems
Systems affected are Red Hat Directory Server versions 11, 12, and 13 that have the Cockpit 389 Console installed. Red Hat Enterprise Linux hosts (versions 6, 7, 8, 9, 10) that include the Cockpit console on a 389-ds-base deployment are also impacted. Plain RHEL installations of 389-ds-base without Cockpit console are not affected.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑severity vulnerability. An attacker must possess LDAP delegated privileges to create or rename entries and a Cockpit administrator must view the entry; both conditions are typically restricted to internal users and administrators, so the exploitation vector is an authenticated, privileged user within the organization. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting no known public exploitation at the time of this analysis. Nonetheless, the severity and potential for execution of arbitrary code under root privileges make it a critical risk for any environment running the affected Cockpit console.
OpenCVE Enrichment