Lucene search

K
nvd[email protected]NVD:CVE-2022-2850
HistoryOct 14, 2022 - 6:15 p.m.

CVE-2022-2850

2022-10-1418:15:14
CWE-476
web.nvd.nist.gov
389-ds-base
content synchronization
authenticated user
null pointer
denial of service
incomplete fix

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

42.7%

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.

Affected configurations

NVD
Node
redhatdirectory_serverMatch11.0
OR
redhatdirectory_serverMatch12.0
OR
redhatenterprise_linuxMatch6.0
OR
redhatenterprise_linuxMatch7.0
OR
redhatenterprise_linuxMatch8.0
OR
redhatenterprise_linuxMatch9.0
Node
fedoraprojectfedoraMatch35
OR
fedoraprojectfedoraMatch36
Node
port389389-ds-baseRange2.0.02.4.1
Node
debiandebian_linuxMatch10.0

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

42.7%