CVE-2013-2219

CWE-2648 documents7 sources
Severity
4.0MEDIUM
EPSS
0.2%
top 61.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 31
Latest updateMay 17

Description

The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

Debian389-ds-base< 1.3.2.9-1+2

🔴Vulnerability Details

3
GHSA
GHSA-8368-c7f9-h333: The Red Hat Directory Server before 82022-05-17
CVEList
CVE-2013-2219: The Red Hat Directory Server before 82013-07-31
OSV
CVE-2013-2219: The Red Hat Directory Server before 82013-07-31

📋Vendor Advisories

2
Red Hat
Server: ACLs inoperative in some search scenarios2013-07-29
Debian
CVE-2013-2219: 389-ds-base - The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not pr...2013

💬Community

2
Bugzilla
CVE-2013-2219 389-ds-base: Directory Server: ACLs inoperative in some search scenarios [fedora-all]2013-07-29
Bugzilla
CVE-2013-2219 Directory Server: ACLs inoperative in some search scenarios2013-06-28
CVE-2013-2219 (MEDIUM CVSS 4) | The Red Hat Directory Server before | cvebase.io