#VU64440 Incorrect authorization in 389-ds-base - CVE-2022-1949
Published: June 16, 2022 / Updated: June 16, 2022
389-ds-base
389 Directory Server Project
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to incorrect authorization in the 389-ds-base package where some LDAP queries can cause performance issues. A remote attacker can send a non-optimal search that causes serious performance issues within the directory server.