CVE-2021-3652
Summary
| CVE | CVE-2021-3652 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-18 17:15:00 UTC |
| Updated | 2023-04-24 09:15:00 UTC |
| Description | A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Port389 | 389-ds-base | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CRYPT password hash with asterisk · Issue #4817 · 389ds/389-ds-base · GitHub | MISC | github.com | |
| [SECURITY] [DLA 3399-1] 389-ds-base security update | MLIST | lists.debian.org | |
| 1982782 – (CVE-2021-3652) CVE-2021-3652 389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159348 Oracle Enterprise Linux Security Update for 389-ds:1.4 (ELSA-2021-3079)
- 159416 Oracle Enterprise Linux Security Update for 389-ds-base (ELSA-2021-3807)
- 181751 Debian Security Update for 389-ds-base (DLA 3399-1)
- 182493 Debian Security Update for 389-ds-base (CVE-2021-3652)
- 239545 Red Hat Update for 389-ds:1.4 (RHSA-2021:3079)
- 239674 Red Hat Update for 389-ds-base (RHSA-2021:3807)
- 239690 Red Hat Update for 389-ds:1.4 (RHSA-2021:3906)
- 257121 CentOS Security Update for 389-ds-base (CESA-2021:3807)
- 353083 Amazon Linux Security Advisory for 389-ds-base : ALAS2-2021-1723
- 354031 Amazon Linux Security Advisory for 389-admin : ALAS-2022-1619
- 354036 Amazon Linux Security Advisory for 389-ds-base : ALAS-2022-1620
- 377336 Alibaba Cloud Linux Security Update for 389-ds:1.4 (ALINUX3-SA-2021:0059)
- 377451 Alibaba Cloud Linux Security Update for 389-ds-base (ALINUX2-SA-2021:0057)
- 671185 EulerOS Security Update for 389-ds-base (EulerOS-SA-2021-2928)
- 671235 EulerOS Security Update for 389-ds-base (EulerOS-SA-2022-1156)
- 672069 EulerOS Security Update for 389-ds-base (EulerOS-SA-2022-2214)
- 751014 OpenSUSE Security Update for 389-ds (openSUSE-SU-2021:2801-1)
- 751064 OpenSUSE Security Update for 389-ds (openSUSE-SU-2021:1211-1)
- 752244 SUSE Enterprise Linux Security Update for 389-ds (SUSE-SU-2022:2109-1)
- 752257 SUSE Enterprise Linux Security Update for 389-ds (SUSE-SU-2022:2163-1)
- 940407 AlmaLinux Security Update for 389-ds:1.4 (ALSA-2021:3079)
- 960792 Rocky Linux Security Update for 389-ds:1.4 (RLSA-2021:3079)