Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-1055
HistoryFeb 27, 2023 - 12:00 a.m.

CVE-2023-1055

2023-02-2700:00:00
ubuntu.com
ubuntu.com
11
rhds
ldap
userpassword
usercertificate
sensitive information
local account
cockpit-389-ds
processes
hashed passwords
data confidentiality
unix

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

13.3%

A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries
to decode the userPassword attribute instead of the userCertificate
attribute which could lead into sensitive information leaked. An attacker
with a local account where the cockpit-389-ds is running can list the
processes and display the hashed passwords. The highest threat from this
vulnerability is to data confidentiality.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

13.3%