CVE-2014-8105: Infoleak
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8105?
CVE-2014-8105 is classified as a medium severity vulnerability due to improper access controls.
How do I fix CVE-2014-8105?
To fix CVE-2014-8105, upgrade to 389 Directory Server version 1.3.2.27 or later for the affected versions.
What types of attacks can be executed using CVE-2014-8105?
CVE-2014-8105 allows remote attackers to exploit insufficient access restrictions to obtain sensitive information from the changelog.
Which versions of software are affected by CVE-2014-8105?
CVE-2014-8105 affects 389 Directory Server versions before 1.3.2.27 and certain 1.3.3.x versions before 1.3.3.9.
Is CVE-2014-8105 related to Federation software?
Yes, CVE-2014-8105 is related to the Red Hat 389 Directory Server and also affects Fedora versions.