Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11087
HistoryJan 15, 2019 - 8:56 a.m.

Information Disclosure

2019-01-1508:56:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

51.3%

redhat-ds-base is vulnerable to information disclosure attacks. The vulnerability exists as the Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute.