VDB

RHSA-2024%3A0278

RHSA-2024%3A0278 PUBLISHED CVSS 5.300000190734863 MEDIUM

A flaw was found in Bouncy Castle 1.73. This issue targets the fix of LDAP wild cards. Before the fix there was no validation for the X.500 name of any certificate, subject, or issuer, so the presence of a wild card may lead to information disclosure. This could allow a malicious user to obtain unauthorized information via blind LDAP Injection, exploring the environment and enumerating data. The exploit depends on the structure of the target LDAP directory as well as what kind of errors are exposed to the user.

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Red HatAMQ Broker 7.11.5

Timeline

  • Jan 17, 2024 CVE Published
  • Mar 26, 2026 CVE Updated
  • May 2, 2026 Distribution Patch
  • May 2, 2026 Distribution Patch
  • May 2, 2026 Security Advisory
  • May 2, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›