CVE-2019-10224
Summary
| CVE | CVE-2019-10224 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-25 16:15:00 UTC |
| Updated | 2023-04-24 09:15:00 UTC |
| Description | A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3399-1] 389-ds-base security update |
MLIST |
lists.debian.org |
|
| Issue #50251: dscreate and dsconf print DM's password in verbose mode - 389-ds-base - Pagure.io |
MISC |
pagure.io |
Third Party Advisory |
| 1677147 – (CVE-2019-10224) CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159651 Oracle Enterprise Linux Security Update for 389-ds:1.4 (ELSA-2019-3401)
- 181751 Debian Security Update for 389-ds-base (DLA 3399-1)