389-ds-base 中发现一个缺陷。 Cockpit 389 控制台的 LDAP 编辑器在构造 命令时,将 LDAP 条目的可分辨名称(DN)直接嵌入到 Shell 命令字符串中,且未进行适当的转义。 拥有目录条目创建或重命名委托权限的 LDAP 用户可以构造一个包含 Shell 元字符(metacharacters)的恶意 DN。当 Cockpit 管理员随后在 389 控制台中查看该条目时,嵌入的 Shell 命令将在目录服务器主机上以 root 权限执行,从而导致命令执行漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Directory Server 11 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Directory Server 12 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Directory Server 13 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | 8080020260903102346.f969626e ~ * |
cpe:/a:redhat:directory_server_e4s:11.7::el8
|
|
| Red Hat | Red Hat Directory Server 11.9 for RHEL 8 | 8100020260904171440.37ed7c03 ~ * |
cpe:/a:redhat:directory_server:11.9::el8
|
|
| Red Hat | Red Hat Directory Server 12.2 E4S for RHEL 9 | 9020020260903155914.1674d574 ~ * |
cpe:/a:redhat:directory_server_e4s:12.2::el9
|
|
| Red Hat | Red Hat Directory Server 12.4 E4S for RHEL 9 | 9040020260903102623.1674d574 ~ * |
cpe:/a:redhat:directory_server_e4s:12.4::el9
|
|
| Red Hat | Red Hat Directory Server 12.6 EUS for RHEL 9 | 9060020260903100230.1674d574 ~ * |
cpe:/a:redhat:directory_server_eus:12.6::el9
|
|
| Red Hat | Red Hat Directory Server 13.0 EUS for RHEL 10 | 0:3.0.6-4.el10dsrv ~ * |
cpe:/a:redhat:directory_server_e2s:13.0::el10
|
|
| Red Hat | Red Hat Directory Server 13.2 for RHEL 10 | 0:3.2.0-7.el10dsrv ~ * |
cpe:/a:redhat:directory_server:13.2::el10
|
|
| Red Hat | Red Hat Directory Server 11 | - |
cpe:/a:redhat:directory_server:11
|
|
| Red Hat | Red Hat Directory Server 12 | - |
cpe:/a:redhat:directory_server:12
|
|
| Red Hat | Red Hat Directory Server 12 | - |
cpe:/a:redhat:directory_server:12
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18922 | 9.8 CRITICAL | 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directo |
| CVE-2026-76578 | 9.8 CRITICAL | Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials vi |
| CVE-2026-86404 | 8.8 HIGH | Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging- |
| CVE-2026-79678 | 8.1 HIGH | Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environm |
| CVE-2026-18453 | 7.5 HIGH | 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results an |
| CVE-2026-18355 | 7.5 HIGH | 389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound |
| CVE-2026-76560 | 7.5 HIGH | 389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empt |
| CVE-2026-86332 | 6.5 MEDIUM | Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user |
| CVE-2026-86469 | 5.3 MEDIUM | Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path |
No comments yet