Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-35518
Description:When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Test IDs: 1.3.6.1.4.1.25623.1.0.879018   1.3.6.1.4.1.25623.1.0.879014   1.3.6.1.4.1.25623.1.0.879013   1.3.6.1.4.1.25623.1.0.853603   1.3.6.1.4.1.25623.1.0.879012   1.3.6.1.4.1.25623.1.0.879017   1.3.6.1.4.1.25623.1.0.879019   1.3.6.1.4.1.25623.1.0.879027   1.3.6.1.4.1.25623.1.0.883357   1.3.6.1.4.1.25623.1.0.879008   1.3.6.1.4.1.25623.1.0.879010   1.3.6.1.4.1.25623.1.0.879026   1.3.6.1.4.1.25623.1.0.879023   1.3.6.1.4.1.25623.1.0.879021  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-35518
https://bugzilla.redhat.com/show_bug.cgi?id=1905565
https://bugzilla.redhat.com/show_bug.cgi?id=1905565
https://github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32
https://github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32
https://github.com/389ds/389-ds-base/commit/cc0f69283abc082488824702dae485b8eae938bc
https://github.com/389ds/389-ds-base/commit/cc0f69283abc082488824702dae485b8eae938bc
https://github.com/389ds/389-ds-base/issues/4480
https://github.com/389ds/389-ds-base/issues/4480




© 1998-2025 E-Soft Inc. All rights reserved.