CVE-2020-35518: Infoleak
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-35518?
CVE-2020-35518 is a vulnerability in 389-ds-base that allows an unauthenticated attacker to check the existence of an entry in the LDAP database.
What is the severity of CVE-2020-35518?
CVE-2020-35518 has a severity score of 5.3, which is considered medium.
Which software versions are affected by CVE-2020-35518?
CVE-2020-35518 affects 389-ds-base versions 1.4.3.19 up to, but not including, 2.0.3.
How can an unauthenticated attacker exploit CVE-2020-35518?
An unauthenticated attacker can exploit CVE-2020-35518 by binding against a DN during authentication and observing the different replies from 389-ds-base to determine the existence of an entry in the LDAP database.
Where can I find more information about CVE-2020-35518?
You can find more information about CVE-2020-35518 at the following references: [Link 1](https://bugzilla.redhat.com/show_bug.cgi?id=1905565), [Link 2](https://github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32), [Link 3](https://github.com/389ds/389-ds-base/commit/cc0f69283abc082488824702dae485b8eae938bc).