First published: Fri Aug 30 2019(Updated: )
A vulnerability was found in 389-ds-base : the `deref` plugin is checking for either READ or SEARCH permission for dereferencing an attribute. This means that the SEARCH permission is sufficient to display an attribute via the plugin. This is relevant in particular in IdM/IPA environment, where a default ACI ("Search existence of password and kerberos keys") in set. This leads to dereferencing able to display userPassword content or any users.
Affected Software | Affected Version | How to fix |
---|---|---|
389 Directory Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1747448 is considered moderate due to its potential impact on sensitive attribute visibility.
To fix REDHAT-BUG-1747448, update your 389 Directory Server to the latest version that addresses this vulnerability.
REDHAT-BUG-1747448 affects the 389 Directory Server software.
REDHAT-BUG-1747448 involves a vulnerability in the deref plugin that improperly checks permissions for dereferencing attributes.
Yes, REDHAT-BUG-1747448 can lead to unauthorized exposure of attributes if adequate permissions are not enforced.