← Back

CVE-2022-1949

nvd nist
Published: Jun 2, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.

Affected (8)

3 products
389 Directory Server
Directory Server
Enterprise Linux
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.3.0.0 to 2.0.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 11.0
Version 12.0
Redhat
Version 8.0
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Version 36

References (2)

Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory

Timeline

No history available yet.