FreeBSD : vault -- User Enumeration via LDAP auth (cc1fd3da-b8fd-4f4d-a092-c38541c0f993)

medium Nessus Plugin ID 144446

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Vault developers report :

Vault allowed enumeration of users via the LDAP auth method. This vulnerability, was fixed in Vault 1.6.1 and 1.5.6.

An external party reported that they were able to enumerate LDAP users via error messages returned by Vault's LDAP auth method

Solution

Update the affected package.

See Also

http://www.nessus.org/u?1a3beee3

http://www.nessus.org/u?2ad2a2c2

Plugin Details

Severity: Medium

ID: 144446

File Name: freebsd_pkg_cc1fd3dab8fd4f4da092c38541c0f993.nasl

Version: 1.4

Type: local

Published: 12/18/2020

Updated: 2/1/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2020-35177

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:vault, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Ease: No known exploits are available

Patch Publication Date: 12/17/2020

Vulnerability Publication Date: 12/16/2020

Reference Information

CVE: CVE-2020-35177