CVE-2019-10224
published 2019-11-25CVE-2019-10224: A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive…
PriorityP418medium4.6CVSS 3.1
AVPACLPRNUINSUCHINAN
EPSS
0.40%
32.0th percentile
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.4.1.5-1 (bookworm) | 389-ds-base 1.4.1.5-1 (bookworm) |
| fedoraproject | 389_directory_server | >= 1.4.0.0 < 1.4.1.3 | 1.4.1.3 |
| port389 | 389-ds-base | >= 0 < 1.4.1.5-1 | 1.4.1.5-1 |
| port389 | 389-ds-base | >= 0 < 1.4.1.5-1 | 1.4.1.5-1 |
| port389 | 389-ds-base | >= 0 < 1.4.1.5-1 | 1.4.1.5-1 |
| red_hat | 389-ds-base | — | — |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.04.3MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-349x-pch6-942w: A flaw has been found in 389-ds-base versions 1
ghsa_unreviewed·2022-05-24
CVE-2019-10224 [MEDIUM] CWE-200 GHSA-349x-pch6-942w: A flaw has been found in 389-ds-base versions 1
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
OSV
CVE-2019-10224: A flaw has been found in 389-ds-base versions 1
osv·2019-11-25·CVSS 4.6
CVE-2019-10224 [MEDIUM] CVE-2019-10224: A flaw has been found in 389-ds-base versions 1
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
Debian
CVE-2019-10224: 389-ds-base - A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When execu...
vendor_debian·2019·CVSS 4.6
CVE-2019-10224 [MEDIUM] CVE-2019-10224: 389-ds-base - A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When execu...
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
Scope: local
bookworm: resolved (fixed in 1.4.1.5-1)
bullseye: resolved (fixed in 1.4.1.5-1)
sid: resolved (fixed in 1.4.1.5-1)
trixie: resolved (fixed in 1.4.1.5-1)
Red Hat
389-ds-base: using dscreate in verbose mode results in information disclosure
vendor_redhat·2018-11-27·CVSS 4.6
CVE-2019-10224 [MEDIUM] CWE-538 389-ds-base: using dscreate in verbose mode results in information disclosure
389-ds-base: using dscreate in verbose mode results in information disclosure
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Not affected
Package: 389-ds-base (Red Hat Enterpris
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10158 infinispan: Session fixation protection broken for Spring Session integration
bugzilla·2019-05-27·CVSS 9.8
CVE-2019-10158 [CRITICAL] CVE-2019-10158 infinispan: Session fixation protection broken for Spring Session integration
CVE-2019-10158 infinispan: Session fixation protection broken for Spring Session integration
A vulnerability was found in Infinispan up to version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration may result in an incorrect session handling
Referrences:
https://issues.jboss.org/browse/ISPN-10224
Upstream Patch:
https://github.com/infinispan/infinispan/pull/6960
Discussion:
Created infinispan tracking bugs for this issue:
Affects: fedora-all [bug 1714360]
---
Red Hat OpenStack - OpenDaylight
This vulnerability is within org.infinispan.spring.common.session which is not included in OpenDaylight.
---
The following products are marked as notaffected because they do not contain the vulnerable library.
* Enterprise Applicatio
Bugzilla
CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure
bugzilla·2019-02-14·CVSS 4.6
CVE-2019-10224 [MEDIUM] CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure
CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure
When dscreate is executed in verbose mode, it prints Directory Manager's password to stderr. The same happens with dsconf when I change the password.
Version-Release number of selected component (if applicable):
389-ds-base-1.4.0.19-2.
How reproducible:
always
Steps to Reproduce:
1. dscreate -v interactive
2. dsconf -v localhost directory_manager password_change
Actual results:
# dscreate -v interactive
...
DEBUG: cn=config set REPLACE: ('nsslapd-rootpw', 'Directory_Manager_Password')
# dsconf -v localhost directory_manager password_change
...
Enter new directory manager password :
CONFIRM - Enter new directory manager password :
DEBUG: cn=config set REPLACE: ('nsslapd-rootpw', 'new_password
Bugzilla
CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure [rhel-8]
bugzilla·2018-11-27·CVSS 4.6
CVE-2019-10224 [MEDIUM] CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure [rhel-8]
CVE-2019-10224 389-ds-base: using dscreate in verbose mode results in information disclosure [rhel-8]
Description of problem:
When dscreate is executed in verbose mode, it prints Directory Manager's password to stderr. The same happens with dsconf when I change the password.
Version-Release number of selected component (if applicable):
389-ds-base-1.4.0.19-2.
How reproducible:
always
Steps to Reproduce:
1. dscreate -v interactive
2. dsconf -v localhost directory_manager password_change
Actual results:
# dscreate -v interactive
...
DEBUG: cn=config set REPLACE: ('nsslapd-rootpw', 'Directory_Manager_Password')
# dsconf -v localhost directory_manager password_change
...
Enter new directory manager password :
CONFIRM - Enter new directory manager password :
DEBUG: cn=config set REPLACE
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10224https://lists.debian.org/debian-lts-announce/2023/04/msg00026.htmlhttps://pagure.io/389-ds-base/issue/50251https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10224https://lists.debian.org/debian-lts-announce/2023/04/msg00026.htmlhttps://pagure.io/389-ds-base/issue/50251
2019-11-25
Published