CVE-2014-0132: Fedoraproject 389 Directory Server
Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.
The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.
Affected products
- Fedoraproject 389 Directory Server: up to and including 1.2.11.25; version 1.2.11.1 only; version 1.2.11.5 only; version 1.2.11.6 only; version 1.2.11.8 only; version 1.2.11.9 only; …
Published 2014-03-18. Last modified 2026-06-17.