REDHAT-BUG-2091781: Medium severity 389 Directory Server 389-ds-base vulnerability
mishandling of the filter that would yield incorrect results, but as that has progressed, we have determined that it actually is an access control bypass. This may allow any remote un-authenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
https://github.com/389ds/389-ds-base/issues/5170
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2091781?
The severity of REDHAT-BUG-2091781 is medium, rated at 4.
What type of vulnerability is REDHAT-BUG-2091781?
REDHAT-BUG-2091781 is an access control bypass vulnerability.
Who is affected by the REDHAT-BUG-2091781 vulnerability?
Remote unauthenticated users of 389 Directory Server are affected by REDHAT-BUG-2091781.
What can REDHAT-BUG-2091781 allow an attacker to do?
REDHAT-BUG-2091781 allows attackers to issue filters that enable them to search for database items they do not have access to.
How can I mitigate the effects of REDHAT-BUG-2091781?
To mitigate REDHAT-BUG-2091781, it is essential to apply security patches and updates provided by the vendor for 389 Directory Server.