It was found that when the nsslapd-unhashed-pw-switch 389 Directory Server configuration option was set to "off", it did not prevent the writing of unhashed passwords into the Changelog. This could potentially allow an authenticated user able to access the Changelog to read sensitive information.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | 389-ds-base | 2015-04-01 13:49 | ALAS-2015-501 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 1.4 | AV:A/AC:H/Au:S/C:P/I:N/A:N |
NVD | CVSSv2 | 4.0 | AV:N/AC:L/Au:S/C:P/I:N/A:N |