First published: Fri Aug 30 2019(Updated: )
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject 389 Directory Server | ||
Redhat Enterprise Linux | =7.0 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14824 is a vulnerability found in the 'deref' plugin of 389-ds-base that allows an authenticated attacker to view private attributes, such as password hashes.
The affected software includes Fedora Project 389 Directory Server, Red Hat Enterprise Linux 7.0, and Debian Linux 8.0.
CVE-2019-14824 has a severity rating of High with a CVSS score of 6.5.
An authenticated attacker could utilize the 'search' permission to display attribute values, potentially accessing private attributes.
To mitigate CVE-2019-14824, it is recommended to update to the latest version of 389-ds-base or apply the available patches from the respective vendors.