CVE-2021-3652
389-ds-base: CRYPT password hash with asterisk allows any bind attempt to succeed
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.
Se ha encontrado un fallo en 389-ds-base. Si es importado un asterisco como hash de la contraseña, ya sea de forma accidental o maliciosa, en lugar de estar inactivo, cualquier contraseña coincidirá con éxito durante la autenticación. Este fallo permite a un atacante autenticarse con éxito como un usuario cuya contraseña estaba deshabilitada
Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol server, as well as command-line utilities and Web UI packages for server administration. This release provides a number of security fixes, bug fixes and enhancements. For detailed information on changes in this release, see the Red Hat Directory Server 11 Release Notes linked from the References section.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-07-16 CVE Reserved
- 2021-08-10 CVE Published
- 2024-08-03 CVE Updated
- 2025-05-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/389ds/389-ds-base/issues/4817 | 2023-04-24 |
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1982782 | 2021-10-25 | |
https://access.redhat.com/security/cve/CVE-2021-3652 | 2021-10-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Port389 Search vendor "Port389" | 389-ds-base Search vendor "Port389" for product "389-ds-base" | < 2.0.7 Search vendor "Port389" for product "389-ds-base" and version " < 2.0.7" | - |
Affected
|