CVE-2023-1055
published 2023-02-27CVE-2023-1055: A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.19%
8.6th percentile
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | 389-ds-base | < 389-ds-base 2.3.4+dfsg1-1 (sid) | 389-ds-base 2.3.4+dfsg1-1 (sid) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| port389 | 389-ds-base | >= 0 < 2.3.4+dfsg1-1 | 2.3.4+dfsg1-1 |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
| redhat | directory_server | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8wv-xqxw-7vgx: A flaw was found in RHDS 11 and RHDS 12
ghsa_unreviewed·2023-02-28
CVE-2023-1055 [MEDIUM] CWE-200 GHSA-w8wv-xqxw-7vgx: A flaw was found in RHDS 11 and RHDS 12
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
OSV
CVE-2023-1055: A flaw was found in RHDS 11 and RHDS 12
osv·2023-02-27·CVSS 5.5
CVE-2023-1055 [MEDIUM] CVE-2023-1055: A flaw was found in RHDS 11 and RHDS 12
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
Red Hat
RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute
vendor_redhat·2023-02-27·CVSS 5.5
CVE-2023-1055 [MEDIUM] CWE-295 RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute
RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in RHDS 11 and 12. While browsing entries, LDAP tries to decode the userPassword attribute instead of the userCertificate attribute, which could lead into sensitive information being leaked. This issue could allow an attacker with a local account with cockpit-389-ds running to list processes a
Debian
CVE-2023-1055: 389-ds-base - A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to de...
vendor_debian·2023·CVSS 5.5
CVE-2023-1055 [MEDIUM] CVE-2023-1055: 389-ds-base - A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to de...
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
Scope: local
bookworm: open
bullseye: open
sid: resolved (fixed in 2.3.4+dfsg1-1)
trixie: resolved (fixed in 2.3.4+dfsg1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2173517#c0https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZOYQ5TCV6ZEPMDV4CSLK3KINAAO4SRI/https://bugzilla.redhat.com/show_bug.cgi?id=2173517#c0https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZOYQ5TCV6ZEPMDV4CSLK3KINAAO4SRI/
2023-02-27
Published