{"api_version":"1","generated_at":"2026-07-23T19:20:00+00:00","cve":"CVE-2021-3652","urls":{"html":"https://cve.report/CVE-2021-3652","api":"https://cve.report/api/cve/CVE-2021-3652.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-3652","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-3652"},"summary":{"title":"CVE-2021-3652","description":"A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2022-04-18 17:15:00","updated_at":"2023-04-24 09:15:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://github.com/389ds/389-ds-base/issues/4817","name":"https://github.com/389ds/389-ds-base/issues/4817","refsource":"MISC","tags":[],"title":"CRYPT password hash with asterisk · Issue #4817 · 389ds/389-ds-base · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html","name":"[debian-lts-announce] 20230424 [SECURITY] [DLA 3399-1] 389-ds-base security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 3399-1] 389-ds-base security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1982782","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1982782","refsource":"MISC","tags":[],"title":"1982782 – (CVE-2021-3652) CVE-2021-3652 389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-3652","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3652","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"3652","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"port389","cpe5":"389-ds-base","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-3652","qid":"159348","title":"Oracle Enterprise Linux Security Update for 389-ds:1.4 (ELSA-2021-3079)"},{"cve":"CVE-2021-3652","qid":"159416","title":"Oracle Enterprise Linux Security Update for 389-ds-base (ELSA-2021-3807)"},{"cve":"CVE-2021-3652","qid":"181751","title":"Debian Security Update for 389-ds-base (DLA 3399-1)"},{"cve":"CVE-2021-3652","qid":"182493","title":"Debian Security Update for 389-ds-base (CVE-2021-3652)"},{"cve":"CVE-2021-3652","qid":"239545","title":"Red Hat Update for 389-ds:1.4 (RHSA-2021:3079)"},{"cve":"CVE-2021-3652","qid":"239674","title":"Red Hat Update for 389-ds-base (RHSA-2021:3807)"},{"cve":"CVE-2021-3652","qid":"239690","title":"Red Hat Update for 389-ds:1.4 (RHSA-2021:3906)"},{"cve":"CVE-2021-3652","qid":"257121","title":"CentOS Security Update for 389-ds-base (CESA-2021:3807)"},{"cve":"CVE-2021-3652","qid":"353083","title":"Amazon Linux Security Advisory for 389-ds-base : ALAS2-2021-1723"},{"cve":"CVE-2021-3652","qid":"354031","title":"Amazon Linux Security Advisory for 389-admin : ALAS-2022-1619"},{"cve":"CVE-2021-3652","qid":"354036","title":"Amazon Linux Security Advisory for 389-ds-base : ALAS-2022-1620"},{"cve":"CVE-2021-3652","qid":"377336","title":"Alibaba Cloud Linux Security Update for 389-ds:1.4 (ALINUX3-SA-2021:0059)"},{"cve":"CVE-2021-3652","qid":"377451","title":"Alibaba Cloud Linux Security Update for 389-ds-base (ALINUX2-SA-2021:0057)"},{"cve":"CVE-2021-3652","qid":"671185","title":"EulerOS Security Update for 389-ds-base (EulerOS-SA-2021-2928)"},{"cve":"CVE-2021-3652","qid":"671235","title":"EulerOS Security Update for 389-ds-base (EulerOS-SA-2022-1156)"},{"cve":"CVE-2021-3652","qid":"672069","title":"EulerOS Security Update for 389-ds-base (EulerOS-SA-2022-2214)"},{"cve":"CVE-2021-3652","qid":"751014","title":"OpenSUSE Security Update for 389-ds (openSUSE-SU-2021:2801-1)"},{"cve":"CVE-2021-3652","qid":"751064","title":"OpenSUSE Security Update for 389-ds (openSUSE-SU-2021:1211-1)"},{"cve":"CVE-2021-3652","qid":"752244","title":"SUSE Enterprise Linux Security Update for 389-ds (SUSE-SU-2022:2109-1)"},{"cve":"CVE-2021-3652","qid":"752257","title":"SUSE Enterprise Linux Security Update for 389-ds (SUSE-SU-2022:2163-1)"},{"cve":"CVE-2021-3652","qid":"940407","title":"AlmaLinux Security Update for 389-ds:1.4 (ALSA-2021:3079)"},{"cve":"CVE-2021-3652","qid":"960792","title":"Rocky Linux Security Update for 389-ds:1.4 (RLSA-2021:3079)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-3652","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"389-ds-base","version":{"version_data":[{"version_value":"389-ds-base 2.0.7"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-287"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1982782","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1982782"},{"refsource":"MISC","name":"https://github.com/389ds/389-ds-base/issues/4817","url":"https://github.com/389ds/389-ds-base/issues/4817"},{"refsource":"MLIST","name":"[debian-lts-announce] 20230424 [SECURITY] [DLA 3399-1] 389-ds-base security update","url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled."}]}},"nvd":{"publishedDate":"2022-04-18 17:15:00","lastModifiedDate":"2023-04-24 09:15:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":2.5},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:port389:389-ds-base:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0.7","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"3652","Ordinal":"212329","Title":"CVE-2021-3652","CVE":"CVE-2021-3652","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"3652","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}