CVE-2021-3652: Medium severity red hat 389 directory server vulnerability
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
Other sources
It was found that invalid password hashes were not correctly handled by 389-ds-base.
Asterisks, '', is a method that can be used in NIS database, or /etc/shadow, to disable an account's password. As a result of the flaw, if an LDAP admin imports such an account from a NIS or /etc/shadow database into Directory Server, any password will be valid for that account.
Reference : https://github.com/389ds/389-ds-base/issues/4817
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3652?
CVE-2021-3652 is a vulnerability found in 389-ds-base that allows an attacker to successfully authenticate as a user whose password was disabled.
How severe is CVE-2021-3652?
CVE-2021-3652 has a severity value of 6.5 (Medium).
What is affected by CVE-2021-3652?
389-ds-base version 2.0.7 is affected by CVE-2021-3652.
How can I fix CVE-2021-3652?
To fix CVE-2021-3652, update 389-ds-base to version 2.0.8 or later.
Where can I find more information about CVE-2021-3652?
More information about CVE-2021-3652 can be found on Red Hat Bugzilla, GitHub, and Debian LTS Announce.