CVE-2019-14824: Medium severity red hat 389 directory server vulnerability
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
Other sources
A vulnerability was found in 389-ds-base : the deref plugin is checking for either READ or SEARCH permission for dereferencing an attribute. This means that the SEARCH permission is sufficient to display an attribute via the plugin.
This is relevant in particular in IdM/IPA environment, where a default ACI ("Search existence of password and kerberos keys") in set. This leads to dereferencing able to display userPassword content or any users.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14824?
CVE-2019-14824 is a vulnerability found in the 'deref' plugin of 389-ds-base that allows an authenticated attacker to view private attributes, such as password hashes.
What software is affected by CVE-2019-14824?
The affected software includes Fedora Project 389 Directory Server, Red Hat Enterprise Linux 7.0, and Debian Linux 8.0.
What is the severity of CVE-2019-14824?
CVE-2019-14824 has a severity rating of High with a CVSS score of 6.5.
How can an attacker exploit CVE-2019-14824?
An authenticated attacker could utilize the 'search' permission to display attribute values, potentially accessing private attributes.
How can CVE-2019-14824 be mitigated?
To mitigate CVE-2019-14824, it is recommended to update to the latest version of 389-ds-base or apply the available patches from the respective vendors.