Back

HIGH

389-ds-base: replication and the Retro Changelog plugin store plaintext password by default

Published Jul 18, 2018

Description

389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.

Affected products

Remediation

Red Hat mitigation

On 389-ds-base 1.3.1 and above: 1- Deactivate clear password storing by default, to prevent new passwords to be logged. -> in cn=config, set nsslapd-unhashed-pw-switch attribute to 'off' or 'nolog' 2- Trim changelog to ensure currently stored passwords are removed. For Replication: -> in cn=changelog5,cn=config, reduce nsslapd-changelogmaxentries, nsslapd-changelogtrim-interval and nsslapd-changelogmaxage -> force a replication & wait for the changelogtrim-interval time -> restore previous values For RetroChangelog: -> deactivate the plugin -> restart directory server -> reactivate the plugin -> restart directory server

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 18, 2018
Updated Aug 5, 2024
Reserved May 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 18, 2018