Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29133
HistoryJan 23, 2021 - 2:17 a.m.

Information Disclosure

2021-01-2302:17:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.001 Low

EPSS

Percentile

45.0%

389-ds-base is vulnerable to information disclosure. The vulnerability exist because the reply from 389-ds-base is different depending on whether the DN exist or not, thus an attacker is able to check the existence of an entry in the LDAP database.