An RODC and a user with the GET_CHANGES right can view all attributes, including secrets and passwords. In Samba's implementation of the DirSync control, Active Directory accounts authorized to do some replication, but not to replicate sensitive attributes, can instead replicate critical domain passwords and secrets. In a default installation, this means that RODC DC accounts (which should only be permitted to replicate some passwords) can instead obtain all domain secrets, including the core AD secret: the krbtgt password. https://bugzilla.samba.org/show_bug.cgi?id=15424
This CVE is now Public: https://www.samba.org/samba/security/CVE-2023-4154.html
Created samba tracking bugs for this issue: Affects: fedora-all [bug 2243230]