CVE-2003-0378Apple MAC OS X vulnerability

2 documents2 sources
Severity
7.5HIGHNVD
EPSS
0.5%
top 34.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 16
Latest updateApr 29

Description

The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDapple/mac_os_x10.2

Patches

🔴Vulnerability Details

1
GHSA
GHSA-78fx-p2gm-vm87: The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to t2022-04-29