389-ds-base version before 1.3.5.19 and 1.3.6.7 are...
Critical severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 13, 2023
Description
Published by the National Vulnerability Database
Aug 16, 2017
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Feb 13, 2023
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
References