CVE-2021-3652

Description

A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw allows an attacker to successfully authenticate as a user whose password was disabled.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.193

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2021:3079) 389-ds:1.4 security and bug fix update 389-ds-base-1.4.3.16-19.module+el8.4.0+11894+f5bb5c43.x86_64.rpmLinux
(RHSA-2021:3079) 389-ds:1.4 security and bug fix update 389-ds-base-debugsource-1.4.3.16-19.module+el8.4.0+11894+f5bb5c43.x86_64.rpmLinux
(RHSA-2021:3079) 389-ds:1.4 security and bug fix update 389-ds-base-devel-1.4.3.16-19.module+el8.4.0+11894+f5bb5c43.x86_64.rpmLinux
(RHSA-2021:3079) 389-ds:1.4 security and bug fix update 389-ds-base-legacy-tools-1.4.3.16-19.module+el8.4.0+11894+f5bb5c43.x86_64.rpmLinux
(RHSA-2021:3079) 389-ds:1.4 security and bug fix update 389-ds-base-libs-1.4.3.16-19.module+el8.4.0+11894+f5bb5c43.x86_64.rpmLinux
(RHSA-2021:3079) 389-ds:1.4 security and bug fix update 389-ds-base-snmp-1.4.3.16-19.module+el8.4.0+11894+f5bb5c43.x86_64.rpmLinux
(RHSA-2021:3079) 389-ds:1.4 security and bug fix update python3-lib389-1.4.3.16-19.module+el8.4.0+11894+f5bb5c43.noarch.rpmLinux
389-ds-base update (ELSA-2021-3079) 389-ds-base-1.4.3.16-19.module+el8.4.0+20279+846fb4fe.x86_64.rpmLinux
389-ds-base-devel update (ELSA-2021-3079) 389-ds-base-devel-1.4.3.16-19.module+el8.4.0+20279+846fb4fe.x86_64.rpmLinux
389-ds-base-legacy-tools update (ELSA-2021-3079) 389-ds-base-legacy-tools-1.4.3.16-19.module+el8.4.0+20279+846fb4fe.x86_64.rpmLinux
389-ds-base-libs update (ELSA-2021-3079) 389-ds-base-libs-1.4.3.16-19.module+el8.4.0+20279+846fb4fe.x86_64.rpmLinux
389-ds-base-snmp update (ELSA-2021-3079) 389-ds-base-snmp-1.4.3.16-19.module+el8.4.0+20279+846fb4fe.x86_64.rpmLinux
Python3-lib389 update (ELSA-2021-3079) python3-lib389-1.4.3.16-19.module+el8.4.0+20279+846fb4fe.noarch.rpmLinux
389-ds-base update (ELSA-2021-3807) 389-ds-base-1.3.10.2-13.el7_9.x86_64.rpmLinux
389-ds-base-devel update (ELSA-2021-3807) 389-ds-base-devel-1.3.10.2-13.el7_9.x86_64.rpmLinux
389-ds-base-libs update (ELSA-2021-3807) 389-ds-base-libs-1.3.10.2-13.el7_9.x86_64.rpmLinux
389-ds-base-snmp update (ELSA-2021-3807) 389-ds-base-snmp-1.3.10.2-13.el7_9.x86_64.rpmLinux
(RHSA-2021:3807) 389-ds-base security and bug fix update 389-ds-base-1.3.10.2-13.el7_9.x86_64.rpmLinux
(RHSA-2021:3807) 389-ds-base security and bug fix update 389-ds-base-devel-1.3.10.2-13.el7_9.x86_64.rpmLinux
(RHSA-2021:3807) 389-ds-base security and bug fix update 389-ds-base-libs-1.3.10.2-13.el7_9.x86_64.rpmLinux
(RHSA-2021:3807) 389-ds-base security and bug fix update 389-ds-base-snmp-1.3.10.2-13.el7_9.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234