Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8: MGASA-2022-0239 Moderate: 389-ds-base Access Control Bypass

mageia
Calendar Grey June 24, 2022
Dist Mageia Esm H88
Vulnerability patched in 389-ds-base; unauthorized access to sensitive data by remote users addressed. Please examine immediately.
An access control bypass vulnerability found in 389-ds-base

Summary

An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data. (CVE-2022-1949)

References

- https://bugs.mageia.org/show_bug.cgi?id=30558

-

- https://www.cve.org/CVERecord?id=CVE-2022-1949

Resolution

SRPMS

- 8/core/389-ds-base-1.4.0.26-8.5.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 24 Jun 2022
URL: https://advisories.mageia.org/MGASA-2022-0239.html
Type: security
CVE: CVE-2022-1949

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here