CVE-2023-1055
RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.
A flaw was found in RHDS 11 and 12. While browsing entries, LDAP tries to decode the userPassword attribute instead of the userCertificate attribute, which could lead into sensitive information being leaked. This issue could allow an attacker with a local account with cockpit-389-ds running to list processes and display hashed passwords. The highest threat is to data confidentiality.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-02-27 CVE Reserved
- 2023-02-27 CVE Published
- 2024-08-02 CVE Updated
- 2024-09-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-295: Improper Certificate Validation
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Directory Server Search vendor "Redhat" for product "Directory Server" | 11.5 Search vendor "Redhat" for product "Directory Server" and version "11.5" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Directory Server Search vendor "Redhat" for product "Directory Server" | 11.6 Search vendor "Redhat" for product "Directory Server" and version "11.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Directory Server Search vendor "Redhat" for product "Directory Server" | 12.0 Search vendor "Redhat" for product "Directory Server" and version "12.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Directory Server Search vendor "Redhat" for product "Directory Server" | 12.1 Search vendor "Redhat" for product "Directory Server" and version "12.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 36 Search vendor "Fedoraproject" for product "Fedora" and version "36" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 37 Search vendor "Fedoraproject" for product "Fedora" and version "37" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 38 Search vendor "Fedoraproject" for product "Fedora" and version "38" | - |
Affected
|