{"api_version":"1","generated_at":"2026-07-23T20:14:32+00:00","cve":"CVE-2019-10224","urls":{"html":"https://cve.report/CVE-2019-10224","api":"https://cve.report/api/cve/CVE-2019-10224.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10224","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10224"},"summary":{"title":"CVE-2019-10224","description":"A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-11-25 16:15:00","updated_at":"2023-04-24 09:15:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html","name":"[debian-lts-announce] 20230424 [SECURITY] [DLA 3399-1] 389-ds-base security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 3399-1] 389-ds-base security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://pagure.io/389-ds-base/issue/50251","name":"https://pagure.io/389-ds-base/issue/50251","refsource":"MISC","tags":["Third Party Advisory"],"title":"Issue #50251: dscreate and dsconf print DM's password in verbose mode - 389-ds-base - Pagure.io","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10224","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10224","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1677147 – (CVE-2019-10224) CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10224","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10224","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10224","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fedoraproject","cpe5":"389_directory_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10224","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fedoraproject","cpe5":"389_directory_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-10224","qid":"159651","title":"Oracle Enterprise Linux Security Update for 389-ds:1.4 (ELSA-2019-3401)"},{"cve":"CVE-2019-10224","qid":"181751","title":"Debian Security Update for 389-ds-base (DLA 3399-1)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-10224","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Red Hat","product":{"product_data":[{"product_name":"389-ds-base","version":{"version_data":[{"version_value":"389-ds-base 1.4.x.x before 1.4.1.3"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-522"}]}]},"references":{"reference_data":[{"url":"https://pagure.io/389-ds-base/issue/50251","refsource":"MISC","name":"https://pagure.io/389-ds-base/issue/50251"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10224","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10224","refsource":"CONFIRM"},{"refsource":"MLIST","name":"[debian-lts-announce] 20230424 [SECURITY] [DLA 3399-1] 389-ds-base security update","url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information."}]},"impact":{"cvss":[[{"vectorString":"4.3/CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.0"}]]}},"nvd":{"publishedDate":"2019-11-25 16:15:00","lastModifiedDate":"2023-04-24 09:15:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.6,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fedoraproject:389_directory_server:*:*:*:*:*:*:*:*","versionStartIncluding":"1.4.0.0","versionEndExcluding":"1.4.1.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10224","Ordinal":"148441","Title":"CVE-2019-10224","CVE":"CVE-2019-10224","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10224","Ordinal":"1","NoteData":"A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10224","Ordinal":"2","NoteData":"2019-11-25","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10224","Ordinal":"3","NoteData":"2019-11-25","Type":"Other","Title":"Modified"}]}}}