CVE-2010-3282
published 2020-01-09CVE-2010-3282: 389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the…
PriorityP410low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.26%
18.0th percentile
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | 389_directory_server | < 1.2.7.1 | 1.2.7.1 |
| hp | hp-ux_directory_server | < b.08.10.03 | b.08.10.03 |
| hp | hp-ux_directory_server | — | — |
| red_hat | 389_directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | redhat_directory_server | < b.08.00.02 | b.08.00.02 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
RHDS/389: information disclosure in audit logs
vendor_redhat·2010-11-12·CVSS 3.3
CVE-2010-3282 [LOW] RHDS/389: information disclosure in audit logs
RHDS/389: information disclosure in audit logs
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact, a future update to Red Hat Directory Server may address this flaw.
Package: Directory Server (Red Hat Directory Server 8) - Affected
GHSA
GHSA-c9g4-pfp3-j9qm: 389 Directory Server before 1
ghsa_unreviewed·2022-04-21
CVE-2010-3282 [LOW] GHSA-c9g4-pfp3-j9qm: 389 Directory Server before 1
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.
No detection rules found.
No public exploits indexed.
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6914https://bugzilla.redhat.com/show_bug.cgi?id=625950https://git.fedorahosted.org/cgit/389/ds.git/commit/?id=d38ae06https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02522633&docLocale=en_UShttp://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6914https://bugzilla.redhat.com/show_bug.cgi?id=625950https://git.fedorahosted.org/cgit/389/ds.git/commit/?id=d38ae06https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c02522633&docLocale=en_US
2020-01-09
Published