Medium severity5.3NVD Advisory· Published Mar 26, 2021· Updated Jun 17, 2026
CVE-2020-35518
CVE-2020-35518
Description
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- 389-ds-base/389-ds-basedescription
- osv-coords2 versionspkg:rpm/opensuse/389-ds&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2
< 1.4.3.19~git0.bef0b5bed-lp152.2.12.1+ 1 more
- (no CPE)range: < 1.4.3.19~git0.bef0b5bed-lp152.2.12.1
- (no CPE)range: < 1.4.3.19~git0.bef0b5bed-3.12.1
cpe:2.3:o:redhat:389_directory_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:389_directory_server:*:*:*:*:*:*:*:*range: <1.4.3.19
- cpe:2.3:a:redhat:directory_server:11.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchVendor Advisory
- github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32nvdPatchThird Party Advisory
- github.com/389ds/389-ds-base/commit/cc0f69283abc082488824702dae485b8eae938bcnvdPatchThird Party Advisory
- github.com/389ds/389-ds-base/issues/4480nvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.