A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-13T16:27:22.527Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14824

No data.

Status : Modified
Published: 2019-11-08T15:15:11.563
Modified: 2024-11-21T04:27:26.460
Link: CVE-2019-14824
