Sensitive information sent insecurely In system.directoryservices.protocols
Description
A flaw was found in dotnet, where the System.DirectoryServices.Protocols.LdapConnection sends credentials in plaintext if the Transport Layer Security (TLS) handshake fails. This flaw allows an attacker to intercept sensitive information. The highest threat from this vulnerability is to confidentiality.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
nuget | 5.0.1 | ||
rpm rhel8 | 0:5.0.208-1.el8_4 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5.