Description
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.
CVSS vector
AV:N/AC:H/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9Complexity: High
Integrity: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-x3v3-65v7-r727: 389 Directory Server before 1↗2022-05-17 ▶ CVEListCVE-2012-2746: 389 Directory Server before 1↗2012-07-03 ▶ OSVCVE-2012-2746: 389 Directory Server before 1↗2012-07-03 ▶ 📋Vendor Advisories
2Red Hatrhds/389: plaintext password disclosure in audit log↗2012-05-10 ▶ DebianCVE-2012-2746: 389-ds-base - 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10...↗2012 ▶ 💬Community
3BugzillaCVE-2012-2678 CVE-2012-2746 389-ds-base various flaws [fedora-all]↗2012-06-26 ▶ BugzillaCVE-2012-2678 CVE-2012-2746 389-ds-base various flaws [epel-5]↗2012-06-26 ▶ BugzillaCVE-2012-2746 rhds/389: plaintext password disclosure in audit log↗2012-06-19 ▶