CVE-2018-10871
published 2018-07-18CVE-2018-10871: 389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog…
PriorityP338high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
1.00%
59.2th percentile
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.4.0.15-1 (bookworm) | 389-ds-base 1.4.0.15-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | 389_directory_server | < 1.3.8.5 | 1.3.8.5 |
| fedoraproject | 389_directory_server | >= 1.4.0.0 < 1.4.0.12 | 1.4.0.12 |
| port389 | 389-ds-base | >= 0 < 1.4.0.15-1 | 1.4.0.15-1 |
| port389 | 389-ds-base | >= 0 < 1.4.0.15-1 | 1.4.0.15-1 |
| port389 | 389-ds-base | >= 0 < 1.4.0.15-1 | 1.4.0.15-1 |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv7.2HIGH
vendor_debian3.8LOW
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pxxp-9p24-326h: 389-ds-base before versions 1
ghsa_unreviewed·2022-05-13
CVE-2018-10871 [HIGH] CWE-312 GHSA-pxxp-9p24-326h: 389-ds-base before versions 1
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.
OSV
CVE-2018-10871: 389-ds-base before versions 1
osv·2018-07-18·CVSS 7.2
CVE-2018-10871 [HIGH] CVE-2018-10871: 389-ds-base before versions 1
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.
Red Hat
389-ds-base: replication and the Retro Changelog plugin store plaintext password by default
vendor_redhat·2018-06-18·CVSS 3.8
CVE-2018-10871 [LOW] CWE-312 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default
389-ds-base: replication and the Retro Changelog plugin store plaintext password by default
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.
By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext
Debian
CVE-2018-10871: 389-ds-base - 389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Stora...
vendor_debian·2018·CVSS 3.8
CVE-2018-10871 [LOW] CVE-2018-10871: 389-ds-base - 389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Stora...
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.
Scope: local
bookworm: resolved (fixed in 1.4.0.15-1)
bullseye: resolved (fixed in 1.4.0.15-1)
sid: resolved (fixed in 1.4.0.15-1)
trixie: resolved (fixed in 1.4.0.15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10871 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default [fedora-all]
bugzilla·2018-06-18·CVSS 3.8
CVE-2018-10871 [LOW] CVE-2018-10871 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default [fedora-all]
CVE-2018-10871 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1591480,1592226
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
Bugzilla
CVE-2018-10871 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default
bugzilla·2018-06-14·CVSS 3.8
CVE-2018-10871 [LOW] CVE-2018-10871 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default
CVE-2018-10871 389-ds-base: replication and the Retro Changelog plugin store plaintext password by default
By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores password in plaintext format in their respective changelog files.
An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.
Discussion:
Created 389-ds-base tracking bugs for this issue:
Affects: fedora-all [bug 1592226]
---
*** Bug 1591481 has been marked as a duplicate of this bug. ***
---
External References:
https://pagure.io/389-ds-base/issue/49789
---
Mitigation:
On 389-ds-base 1.3.1 and above:
1- Deactivate clear password storing by default, to prevent new passwords to be logged.
-> in cn=c
https://access.redhat.com/errata/RHSA-2019:3401https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10871https://lists.debian.org/debian-lts-announce/2018/08/msg00032.htmlhttps://pagure.io/389-ds-base/issue/49789https://access.redhat.com/errata/RHSA-2019:3401https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10871https://lists.debian.org/debian-lts-announce/2018/08/msg00032.htmlhttps://pagure.io/389-ds-base/issue/49789
2018-07-18
Published