Back to bug 2173517

Who When What Removed Added
Avinash Hanwate 2023-02-27 10:49:32 UTC Alias CVE-2023-1055
Summary RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute CVE-2023-1055 RHDS: LDAP browser tries to decode userPassword instead of userCertificate attribute
Avinash Hanwate 2023-02-27 10:52:31 UTC Blocks 2173596
Borja Tarraso 2023-02-27 14:40:56 UTC Depends On 2173629, 2173628
Borja Tarraso 2023-02-27 15:42:26 UTC Depends On 2173675, 2173676
Paige Jung 2023-02-27 16:10:09 UTC Doc Text A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality. A flaw was found in RHDS 11 and 12. While browsing entries, LDAP tries to decode the userPassword attribute instead of the userCertificate attribute, which could lead into sensitive information being leaked. This issue could allow an attacker with a local account with cockpit-389-ds running to list processes and display hashed passwords. The highest threat is to data confidentiality.
Sandipan Roy 2023-02-28 04:24:44 UTC Depends On 2173829, 2173830
errata-xmlrpc 2023-06-06 13:05:47 UTC Depends On 2177929
Depends On 2177930
Depends On 2178131
Depends On 2178135
Depends On 2178157
Link ID Red Hat Product Errata RHSA-2023:3489
Red Hat Bugzilla 2023-07-07 08:34:34 UTC Assignee security-response-team nobody
errata-xmlrpc 2023-08-15 14:11:53 UTC Link ID Red Hat Product Errata RHSA-2023:4655

Back to bug 2173517