Enabled default configuration In 389-ds-base
Description
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 1.3.3.5-4 | ||
debian 11 | 1.3.3.5-4 | ||
debian 12 | 1.3.3.5-4 | ||
rpm rhel7 | 0:1.3.3.1-13.el7 |
Aliases
1. 2. 3. 4. 5.