CVE-2019-14824
Summary
| CVE | CVE-2019-14824 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-08 15:15:00 UTC |
| Updated | 2023-04-24 09:15:00 UTC |
| Description | A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1747448 – (CVE-2019-14824) CVE-2019-14824 389-ds-base: Read permission check bypass via the deref plugin |
MISC |
bugzilla.redhat.com |
|
| Issue #50716: deref plugin displays restricted attributes - 389-ds-base - Pagure.io |
MISC |
pagure.io |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| [SECURITY] [DLA 3399-1] 389-ds-base security update |
MISC |
lists.debian.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Vendor Advisory |
| 1747448 – (CVE-2019-14824) CVE-2019-14824 389-ds-base: Read permission check bypass via the deref plugin |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Vendor Advisory |
| [SECURITY] [DLA 2004-1] 389-ds-base security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159651 Oracle Enterprise Linux Security Update for 389-ds:1.4 (ELSA-2019-3401)
- 181751 Debian Security Update for 389-ds-base (DLA 3399-1)
- 377215 Alibaba Cloud Linux Security Update for 389-ds-base (ALINUX2-SA-2019:0122)
- 378255 Virtuozzo Linux Security Update for 389-ds-base-snmp (VZLSA-2019:3981)