Name | CVE-2019-14824 |
Description | A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-2004-1, DLA-3399-1 |
Debian Bugs | 944150 |
The table below lists information on source packages.
The information below is based on the following data on fixed versions.