krb5: DN container check bypass by supplying special crafted data
Published Mar 6, 2018
3.8
LOWCVSS 3.1
EPSS 2.24%
Description
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
Affected products
No data.
Configuration 1
- ≥ 5-1.6 · < 5-1.21.2
Configuration 2
- 26
- 27
Configuration 3
- 8.0
- 9.0
Configuration 4
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 7
krb5-0:1.15.1-34.el7
Fixed · RHSA-2018:3071
Red Hat Enterprise Linux 5
krb5
Will not fix
Red Hat Enterprise Linux 6
krb5
Will not fix
Red Hat Enterprise Linux 8
krb5
Not affected
Red Hat JBoss Core Services
krb5
Not affected
Red Hat JBoss Enterprise Application Platform 6
krb5
Will not fix
Red Hat JBoss Enterprise Web Server 2
krb5
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | krb5-0:1.15.1-34.el7 | Fixed | RHSA-2018:3071 |
| Red Hat Enterprise Linux 5 | krb5 | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | krb5 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | krb5 | Not affected | n/a |
| Red Hat JBoss Core Services | krb5 | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | krb5 | Will not fix | n/a |
| Red Hat JBoss Enterprise Web Server 2 | krb5 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
AV:N/AC:L/Au:S/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.24% (0.02236) | 82.18th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.25% (0.02251) | 80.57th | v5 (v2026.06.15) |
| Mar 17, 2025 | 1.35% (0.01346) | 78.71th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.16% (0.00162) | 54.19th | v3 (v2023.03.01) |
| May 24, 2024 | 0.16% (0.00162) | 52.79th | v3 (v2023.03.01) |
| Sep 30, 2023 | 0.15% (0.00155) | 51.45th | v3 (v2023.03.01) |
| Sep 6, 2023 | 0.20% (0.00198) | 56.95th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.23% (0.00234) | 60.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00243) | 60.43th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Oct 11, 2021 | 2.27% (0.02273) | 78.15th | v1 |
| Oct 5, 2021 | 9.45% (0.09448) | 93.95th | v1 |
| Oct 4, 2021 | 2.27% (0.02273) | 77.89th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.07% (0.02069) | 0.00th | v1 |
References (13)
- http://www.securitytracker.com/id/1042071 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3071 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-5730 Vendor Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=891869 x_refsource_CONFIRMThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1551082 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/krb5/krb5/commit/e1caf6fb74981da62039846931ebdffed71309d1 x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00020.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/09/msg00019.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GK5T6JPMBHBPKS7HNGHYUUF4KKRMNSNU/ vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OIFUL3CPM4S5TOXTTOCQ3CUZN6XCXUTR/ vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-5730
- https://www.cve.org/CVERecord?id=CVE-2018-5730
Change history (0)
No recorded changes yet.