CVE-2020-35518
published 2021-03-26CVE-2020-35518: When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.54%
72.1th percentile
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.4.4.10-1 (bookworm) | 389-ds-base 1.4.4.10-1 (bookworm) |
| port389 | 389-ds-base | >= 0 < 1.4.4.10-1 | 1.4.4.10-1 |
| port389 | 389-ds-base | >= 0 < 1.4.4.10-1 | 1.4.4.10-1 |
| port389 | 389-ds-base | >= 0 < 1.4.4.10-1 | 1.4.4.10-1 |
| port389 | 389-ds-base | >= 0 < 1.3.4.9-1ubuntu0.1~esm1 | 1.3.4.9-1ubuntu0.1~esm1 |
| port389 | 389-ds-base | >= 0 < 1.3.7.10-1ubuntu1+esm1 | 1.3.7.10-1ubuntu1+esm1 |
| port389 | 389-ds-base | >= 0 < 1.4.3.6-2ubuntu0.1~esm1 | 1.4.3.6-2ubuntu0.1~esm1 |
| redhat | 389_directory_server | < 1.4.3.19 | 1.4.3.19 |
| redhat | 389_directory_server | >= 1.4.4.0 < 1.4.4.13 | 1.4.4.13 |
| redhat | 389_directory_server | >= 2.0.0 < 2.0.3 | 2.0.3 |
| redhat | directory_server | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
389-ds-base vulnerabilities
osv·2022-07-18·CVSS 5.3
CVE-2020-35518 [MEDIUM] 389-ds-base vulnerabilities
389-ds-base vulnerabilities
It was discovered that 389 Directory Server presented to users, during
authentication, an error message which could be used to discover if a
certain LDAP DN existed or not. A remote unauthenticated attacker could
possibly use this to check the existence of an entry in a LDAP database
and expose sensitive information. This issue affected only Ubuntu 20.04
ESM. (CVE-2020-35518)
It was discovered that 389 Directory Server was incorrectly validating
data used to access memory addresses. An authenticated attacker using a
Syncrepl client could use this issue with a specially crafted query to
cause 389 Directory Server to crash, resulting in a denial of service.
(CVE-2021-3514)
GHSA
GHSA-vg4h-9m5m-rchq: When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not
ghsa_unreviewed·2022-05-24
CVE-2020-35518 [MEDIUM] CWE-200 GHSA-vg4h-9m5m-rchq: When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
OSV
CVE-2020-35518: When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not
osv·2021-03-26·CVSS 5.3
CVE-2020-35518 [MEDIUM] CVE-2020-35518: When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Ubuntu
389 Directory Server vulnerabilities
vendor_ubuntu·2022-07-18·CVSS 5.3
CVE-2020-35518 [MEDIUM] 389 Directory Server vulnerabilities
Title: 389 Directory Server vulnerabilities
Summary: Several security issues were fixed in 389 Directory Server.
It was discovered that 389 Directory Server presented to users, during
authentication, an error message which could be used to discover if a
certain LDAP DN existed or not. A remote unauthenticated attacker could
possibly use this to check the existence of an entry in a LDAP database
and expose sensitive information. This issue affected only Ubuntu 20.04
ESM. (CVE-2020-35518)
It was discovered that 389 Directory Server was incorrectly validating
data used to access memory addresses. An authenticated attacker using a
Syncrepl client could use this issue with a specially crafted query to
cause 389 Directory Server to crash, resulting in a denial of service.
(CVE-2021-3514)
Ins
Red Hat
389-ds-base: information disclosure during the binding of a DN
vendor_redhat·2020-12-07·CVSS 5.3
CVE-2020-35518 [MEDIUM] CWE-200 389-ds-base: information disclosure during the binding of a DN
389-ds-base: information disclosure during the binding of a DN
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Out of support scope
Package: 389-ds-base (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2020-35518: 389-ds-base - When binding against a DN during authentication, the reply from 389-ds-base will...
vendor_debian·2020·CVSS 5.3
CVE-2020-35518 [MEDIUM] CVE-2020-35518: 389-ds-base - When binding against a DN during authentication, the reply from 389-ds-base will...
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Scope: local
bookworm: resolved (fixed in 1.4.4.10-1)
bullseye: resolved (fixed in 1.4.4.10-1)
sid: resolved (fixed in 1.4.4.10-1)
trixie: resolved (fixed in 1.4.4.10-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1905565https://github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32https://github.com/389ds/389-ds-base/commit/cc0f69283abc082488824702dae485b8eae938bchttps://github.com/389ds/389-ds-base/issues/4480https://bugzilla.redhat.com/show_bug.cgi?id=1905565https://github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32https://github.com/389ds/389-ds-base/commit/cc0f69283abc082488824702dae485b8eae938bchttps://github.com/389ds/389-ds-base/issues/4480
2021-03-26
Published