CVE-2023-1055

MEDIUM

Red Hat Directory Server 11 and 12 - Sensitive Information Disclosure via UserPassword Attribute Misdirection

Title source: llm
STIX 2.1

Description

A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.

References (2)

Core 2

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 19.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295 CWE-200
Status published
Products (7)
fedoraproject/fedora 36
fedoraproject/fedora 37
fedoraproject/fedora 38
redhat/directory_server 11.5
redhat/directory_server 11.6
redhat/directory_server 12.0
redhat/directory_server 12.1
Published Feb 27, 2023
Tracked Since Feb 18, 2026