CVE-2012-2678: Fedoraproject 389 Directory Server

Low severity, CVSS 1.2. EPSS: 0.6% chance of exploitation in the next 30 days.

389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.

Affected products

  • Fedoraproject 389 Directory Server: up to and including 1.2.11.5; version 1.2.1 only; version 1.2.2 only; version 1.2.3 only; version 1.2.5 only; version 1.2.6 only; …
  • Red Hat Directory Server: up to and including 8.2; version 7.1 only; version 8.0 only; version 8.1 only

Published 2012-07-03. Last modified 2026-06-16.