VDB
RHSA-2024%3A0278
RHSA-2024%3A0278
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in Bouncy Castle 1.73. This issue targets the fix of LDAP wild cards. Before the fix there was no validation for the X.500 name of any certificate, subject, or issuer, so the presence of a wild card may lead to information disclosure. This could allow a malicious user to obtain unauthorized information via blind LDAP Injection, exploring the environment and enumerating data. The exploit depends on the structure of the target LDAP directory as well as what kind of errors are exposed to the user.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | AMQ Broker 7.11.5 |
Timeline
- Jan 17, 2024 CVE Published
- Mar 26, 2026 CVE Updated
- May 2, 2026 Distribution Patch
- May 2, 2026 Distribution Patch
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:0278 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.11.5 advisory
- https://access.redhat.com/documentation/en-us/red_hat_amq_broker/7.11 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2215465 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0278.json advisory
- https://access.redhat.com/security/cve/CVE-2023-33201 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-33201 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-33201 advisory
- https://github.com/bcgit/bc-java/wiki/CVE-2023-33201 advisory