A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2019:3981 | Vendor Advisory |
https://access.redhat.com/errata/RHSA-2020:0464 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14824 | Issue Tracking Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2019/11/msg00036.html | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html | |
https://access.redhat.com/errata/RHSA-2019:3981 | Vendor Advisory |
https://access.redhat.com/errata/RHSA-2020:0464 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14824 | Issue Tracking Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2019/11/msg00036.html | Mailing List Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html |
Configurations
History
21 Nov 2024, 04:27
Type | Values Removed | Values Added |
---|---|---|
References | () https://access.redhat.com/errata/RHSA-2019:3981 - Vendor Advisory | |
References | () https://access.redhat.com/errata/RHSA-2020:0464 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14824 - Issue Tracking, Vendor Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/11/msg00036.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html - |
Information
Published : 2019-11-08 15:15
Updated : 2024-11-21 04:27
NVD link : CVE-2019-14824
Mitre link : CVE-2019-14824
CVE.ORG link : CVE-2019-14824
JSON object : View
Products Affected
debian
- debian_linux
fedoraproject
- 389_directory_server
redhat
- enterprise_linux
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource