CVE-2018-10871 Details
Description
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:3401 | CVE | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10871 | CVE | Issue TrackingMitigationThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2018/08/msg00032.html | CVE | Mailing ListThird Party Advisory |
| https://pagure.io/389-ds-base/issue/49789 | CVE | Issue TrackingThird Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:3401 | [email protected] | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10871 | [email protected] | Issue TrackingMitigationThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2018/08/msg00032.html | [email protected] | Mailing ListThird Party Advisory |
| https://pagure.io/389-ds-base/issue/49789 | [email protected] | Issue TrackingThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| fedoraproject 389 directory server | < 1.3.8.5 >= 1.4.0.0, < 1.4.0.12 |
CPE
Remediation
| |
| debian debian linux | 8.0 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 6, 2019 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Sep 17, 2018 | Initial Analysis | [email protected] |
| Aug 31, 2018 | CVE Modified | [email protected] |