389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade 389-ds-base | Jul 30, 2024 | Mar 10, 2015 |
| Oracle_linux | — | Upgrade 389-ds-baseUpgrade 389-ds-base-develUpgrade 389-ds-base-libs | Oct 16, 2024 | Mar 10, 2015 |
| Suse | — | Upgrade libsvrcore0Upgrade lib389Upgrade 389-ds-develUpgrade 389-ds | Feb 4, 2022 | Mar 10, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub