cbcvebase.
CVE-2018-14628
published 2023-01-17

CVE-2018-14628: An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could…

PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.17%
64.1th percentile
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiansamba< samba 2:4.17.12+dfsg-0+deb12u3 (bookworm)samba 2:4.17.12+dfsg-0+deb12u3 (bookworm)
fedoraprojectfedora
msrccbl2_samba_4.12.5-6_on_cbl_mariner_2.0
sambasamba
sambasamba>= 0 < 2:4.17.12+dfsg-0+deb12u32:4.17.12+dfsg-0+deb12u3
sambasamba>= 0 < 2:4.19.3+dfsg-12:4.19.3+dfsg-1
sambasamba>= 0 < 2:4.19.3+dfsg-12:4.19.3+dfsg-1
sambasamba>= 4.0.0 < 4.18.94.18.9
sambasamba>= 4.19.0 < 4.19.34.19.3

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.