Business information leak In 389-ds-base
Description
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 1.4.2.4-1 | ||
debian 12 | 1.4.2.4-1 | ||
debian 11 | 1.4.2.4-1 | ||
rpm rhel7 | 0:1.3.9.1-12.el7_7 | ||
rpm rhel6 | - | - |
Aliases
1. 2. 3. 4. 5.