cbcvebase.
CVE-2019-10224
published 2019-11-25

CVE-2019-10224: A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive…

PriorityP418medium4.6CVSS 3.1
AVPACLPRNUINSUCHINAN
EPSS
0.40%
32.0th percentile
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.

Affected

6 ranges
VendorProductVersion rangeFixed in
debian389-ds-base< 389-ds-base 1.4.1.5-1 (bookworm)389-ds-base 1.4.1.5-1 (bookworm)
fedoraproject389_directory_server>= 1.4.0.0 < 1.4.1.31.4.1.3
port389389-ds-base>= 0 < 1.4.1.5-11.4.1.5-1
port389389-ds-base>= 0 < 1.4.1.5-11.4.1.5-1
port389389-ds-base>= 0 < 1.4.1.5-11.4.1.5-1
red_hat389-ds-base

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.04.3MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.