CVE-2014-8112
published 2015-03-10CVE-2014-8112: 389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option…
PriorityP417medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.69%
74.6th percentile
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.3.3.5-4 (bookworm) | 389-ds-base 1.3.3.5-4 (bookworm) |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
| fedoraproject | 389_directory_server | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jpqj-372q-hwmp: 389 Directory Server 1
ghsa_unreviewed·2022-05-17
CVE-2014-8112 [MEDIUM] CWE-200 GHSA-jpqj-372q-hwmp: 389 Directory Server 1
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
OSV
CVE-2014-8112: 389 Directory Server 1
osv·2015-03-10·CVSS 4.0
CVE-2014-8112 [MEDIUM] CVE-2014-8112: 389 Directory Server 1
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
Red Hat
389-ds-base: password hashing bypassed when "nsslapd-unhashed-pw-switch" is set to off
vendor_redhat·2015-03-05·CVSS 4.0
CVE-2014-8112 [MEDIUM] CWE-522 389-ds-base: password hashing bypassed when "nsslapd-unhashed-pw-switch" is set to off
389-ds-base: password hashing bypassed when "nsslapd-unhashed-pw-switch" is set to off
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
It was found that when the nsslapd-unhashed-pw-switch 389 Directory Server configuration option was set to "off", it did not prevent the writing of unhashed passwords into the Changelog. This could potentially allow an authenticated user able to access the Changelog to read sensitive information.
Statement: This issue did not affect the versions of 389-ds-base as shipped with Red Hat Enterprise Linux 6.
Package: 389-ds-base (Red Hat E
Debian
CVE-2014-8112: 389-ds-base - 389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3....
vendor_debian·2014·CVSS 4.0
CVE-2014-8112 [MEDIUM] CVE-2014-8112: 389-ds-base - 389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3....
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
Scope: local
bookworm: resolved (fixed in 1.3.3.5-4)
bullseye: resolved (fixed in 1.3.3.5-4)
sid: resolved (fixed in 1.3.3.5-4)
trixie: resolved (fixed in 1.3.3.5-4)
No detection rules found.
Bugzilla
CVE-2014-8112 CVE-2014-8105 389-ds-base: various flaws [fedora-all]
bugzilla·2015-03-07·CVSS 5.0
CVE-2014-8112 [MEDIUM] CVE-2014-8112 CVE-2014-8105 389-ds-base: various flaws [fedora-all]
CVE-2014-8112 CVE-2014-8105 389-ds-base: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2014-8112 389-ds-base: password hashing bypassed when "nsslapd-unhashed-pw-switch" is set to off
bugzilla·2014-12-10·CVSS 4.0
CVE-2014-8112 [MEDIUM] CVE-2014-8112 389-ds-base: password hashing bypassed when "nsslapd-unhashed-pw-switch" is set to off
CVE-2014-8112 389-ds-base: password hashing bypassed when "nsslapd-unhashed-pw-switch" is set to off
Ludwig Krispenz from Red Hat reported that there is a configuration switch to prevent writing unhashed passwords into the changelogs. Unfortunately if the switch is turned on the attribute unhashed#user#password is not written to the changelog, but the hashing of the attribute value itself is also bypassed.
Versions affected are 389 versions 1.3.1 and later, this means RHEL7.0 and later and Fedora20 and later.
The severity seems to be limited, since:
- the option is not widely known and advertised and only available in a recent version
- the access to the userpassword attribute is usually protected by acis not to be readable
Statement:
This issue did not affect the versions of 389-ds-b
http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-2-27.htmlhttp://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-9.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153991.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0416.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1172729http://directory.fedoraproject.org/docs/389ds/releases/release-1-3-2-27.htmlhttp://directory.fedoraproject.org/docs/389ds/releases/release-1-3-3-9.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153991.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0416.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1172729
2015-03-10
Published