CVE-2020-35518
Summary
| CVE | CVE-2020-35518 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-26 17:15:00 UTC |
| Updated | 2022-08-05 17:42:00 UTC |
| Description | When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1905565 – (CVE-2020-35518) CVE-2020-35518 389-ds-base: information disclosure during the binding of a DN |
MISC |
bugzilla.redhat.com |
|
| Issue 4609 - CVE - info disclosure when authenticating · 389ds/389-ds-base@b6aae4d · GitHub |
MISC |
github.com |
|
| Unexpected info returned to ldap request · Issue #4480 · 389ds/389-ds-base · GitHub |
MISC |
github.com |
|
| Issue 4480 - Unexpected info returned to ldap request (#4491) · 389ds/389-ds-base@cc0f692 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159143 Oracle Enterprise Linux Security Update for 389-ds:1.4 (ELSA-2021-1086)
- 159253 Oracle Enterprise Linux Security Update for 389-ds-base (ELSA-2021-2323)
- 174763 SUSE Enterprise Linux Security update for 389-ds (SUSE-SU-2021:0724-1)
- 239203 Red Hat Update for 389-ds:1.4 (RHSA-2021:1086)
- 239240 Red Hat Update for 389-ds:1.4 (RHSA-2021:1258)
- 239400 Red Hat Update for 389-ds-base (RHSA-2021:2323)
- 257088 CentOS Security Update for 389-ds-base (CESA-2021:2323)
- 281585 Fedora Security Update for 389 (FEDORA-2021-dc1a4934a5)
- 281586 Fedora Security Update for 389 (FEDORA-2021-7458e2d835)
- 281587 Fedora Security Update for 389 (FEDORA-2021-263244c071)
- 352405 Amazon Linux Security Advisory for 389-ds-base: ALAS2-2021-1650
- 377384 Alibaba Cloud Linux Security Update for 389-ds:1.4 (ALINUX3-SA-2021:0024)
- 377540 Alibaba Cloud Linux Security Update for 389-ds-base (ALINUX2-SA-2021:0036)
- 750309 OpenSUSE Security Update for 389-ds (openSUSE-SU-2021:0418-1)