在 389 Directory Server 中发现了一个漏洞。 在 SASL PLAIN 认证过程中,来自之前一次失败绑定尝试的过期身份标识,会通过 Cyrus SASL 辅助属性保留在连接中,并可能在随后一次不相关的成功绑定中生效,无论该次绑定是通过哪种 SASL 机制完成的。 攻击者可以发送一个使用 账户但密码错误的 SASL PLAIN 绑定,然后在同一连接上完成一个 SASL ANONYMOUS 绑定,从而使得服务器在没有任何有效凭据的情况下,仍会授予 Directory Manager 权限。此外,还可
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Directory Server 11 | any |
affected |
| Red Hat | Red Hat Directory Server 12 | any |
affected |
| Red Hat | Red Hat Directory Server 13 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | 8080020260903102346.f969626e ~ * |
cpe:/a:redhat:directory_server_e4s:11.7::el8
|
|
| Red Hat | Red Hat Directory Server 11.9 for RHEL 8 | 8100020260904171440.37ed7c03 ~ * |
cpe:/a:redhat:directory_server:11.9::el8
|
|
| Red Hat | Red Hat Directory Server 12.2 E4S for RHEL 9 | 9020020260903155914.1674d574 ~ * |
cpe:/a:redhat:directory_server_e4s:12.2::el9
|
|
| Red Hat | Red Hat Directory Server 12.4 E4S for RHEL 9 | 9040020260903102623.1674d574 ~ * |
cpe:/a:redhat:directory_server_e4s:12.4::el9
|
|
| Red Hat | Red Hat Enterprise Linux 10 | 0:3.2.0-10.el10_2 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:3.0.6-21.el10_0 ~ * |
cpe:/o:redhat:enterprise_linux_eus:10.0
|
|
| Red Hat | Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | 0:1.2.11.15-97.el6_10.1 ~ * |
cpe:/o:redhat:rhel_els:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:1.3.11.1-15.el7_9 ~ * |
cpe:/o:redhat:rhel_els:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 8100020260904155442.25e700aa ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 8040020260901171549.96015a92 ~ * |
cpe:/a:redhat:rhel_aus:8.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 8040020260901171549.96015a92 ~ * |
cpe:/a:redhat:rhel_aus:8.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 8060020260901145727.824efc52 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 8060020260901145727.824efc52 ~ * |
cpe:/a:redhat:rhel_aus:8.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 8080020260831180218.6dbb3803 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 8080020260831180218.6dbb3803 ~ * |
cpe:/a:redhat:rhel_e4s:8.8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.8.0-10.el9_8 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:2.2.4-22.el9_2 ~ * |
cpe:/a:redhat:rhel_e4s:9.2::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:2.4.5-29.el9_4 ~ * |
cpe:/a:redhat:rhel_e4s:9.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:2.6.1-24.el9_6 ~ * |
cpe:/a:redhat:rhel_eus:9.6::appstream
|
|
| Red Hat | Red Hat Directory Server 12 | - |
cpe:/a:redhat:directory_server:12
|
|
| Red Hat | Red Hat Directory Server 13 | - |
cpe:/a:redhat:directory_server:13
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76578 | 9.8 CRITICAL | Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials vi |
| CVE-2026-86404 | 8.8 HIGH | Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging- |
| CVE-2026-19843 | 8.4 HIGH | 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console l |
| CVE-2026-79678 | 8.1 HIGH | Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environm |
| CVE-2026-18453 | 7.5 HIGH | 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results an |
| CVE-2026-18355 | 7.5 HIGH | 389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound |
| CVE-2026-76560 | 7.5 HIGH | 389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empt |
| CVE-2026-86332 | 6.5 MEDIUM | Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user |
| CVE-2026-86469 | 5.3 MEDIUM | Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path |
No comments yet