CVE-2014-8112
Public on 2015-03-10
Modified on 2015-04-01
Description
It was found that when the nsslapd-unhashed-pw-switch 389 Directory Server configuration option was set to "off", it did not prevent the writing of unhashed passwords into the Changelog. This could potentially allow an authenticated user able to access the Changelog to read sensitive information.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | 389-ds-base | 2015-04-01 | ALAS-2015-501 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 1.4 | AV:A/AC:H/Au:S/C:P/I:N/A:N |
NVD | CVSSv2 | 4.0 | AV:N/AC:L/Au:S/C:P/I:N/A:N |