VDB
ALINUX2-SA-2019%3A0122
ALINUX2-SA-2019%3A0122
PUBLISHED
CVSS 6.5 MEDIUM
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-14824: A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
Risk Scores
CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | 389-ds-base |
Timeline
- Dec 7, 2019 CVE Published
- Dec 7, 2019 CVE Updated