#VU23002 Information disclosure in 389-ds-base - CVE-2019-14824
Published: November 26, 2019
389-ds-base
389 Directory Server Project
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to incorrect permissions in the 'deref' plugin in 389-ds-base when displaying attribute values during search. A remote user in local network can gain access to private attributes, such as password hashes.