CVE-2021-3652
published 2022-04-18CVE-2021-3652: A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.43%
70.1th percentile
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 1.4.4.17-1 (bookworm) | 389-ds-base 1.4.4.17-1 (bookworm) |
| port389 | 389-ds-base | < 2.0.7 | 2.0.7 |
| port389 | 389-ds-base | — | — |
| port389 | 389-ds-base | >= 0 < 1.4.4.11-2+deb11u1 | 1.4.4.11-2+deb11u1 |
| port389 | 389-ds-base | >= 0 < 1.4.4.17-1 | 1.4.4.17-1 |
| port389 | 389-ds-base | >= 0 < 1.4.4.17-1 | 1.4.4.17-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qc73-mcqm-3m29: A flaw was found in 389-ds-base
ghsa_unreviewed·2022-04-19
CVE-2021-3652 [CRITICAL] CWE-287 GHSA-qc73-mcqm-3m29: A flaw was found in 389-ds-base
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
OSV
CVE-2021-3652: A flaw was found in 389-ds-base
osv·2022-04-18·CVSS 6.5
CVE-2021-3652 [MEDIUM] CVE-2021-3652: A flaw was found in 389-ds-base
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
Red Hat
389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
vendor_redhat·2021-06-29·CVSS 6.5
CVE-2021-3652 [MEDIUM] CWE-287 389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
Package: 389-ds-base (Red Hat Enterprise Linux 6) - Out of support scope
Package: 389-ds-base (Red Hat E
Debian
CVE-2021-3652: 389-ds-base - A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, ...
vendor_debian·2021·CVSS 6.5
CVE-2021-3652 [MEDIUM] CVE-2021-3652: 389-ds-base - A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, ...
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
Scope: local
bookworm: resolved (fixed in 1.4.4.17-1)
bullseye: resolved (fixed in 1.4.4.11-2+deb11u1)
sid: resolved (fixed in 1.4.4.17-1)
trixie: resolved (fixed in 1.4.4.17-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1982782https://github.com/389ds/389-ds-base/issues/4817https://lists.debian.org/debian-lts-announce/2023/04/msg00026.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1982782https://github.com/389ds/389-ds-base/issues/4817https://lists.debian.org/debian-lts-announce/2023/04/msg00026.htmlhttps://lists.debian.org/debian-lts-announce/2025/01/msg00015.html
2022-04-18
Published