CVE-2014-8112: Fedoraproject 389 Directory Server

Medium severity, CVSS 4.0. EPSS: 1.7% chance of exploitation in the next 30 days.

389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.

Affected products

  • Fedoraproject 389 Directory Server: version 1.3.1.0 only; version 1.3.1.1 only; version 1.3.1.2 only; version 1.3.1.3 only; version 1.3.1.4 only; version 1.3.1.5 only; …
  • Fedoraproject Fedora: version 22 only

Published 2015-03-10. Last modified 2026-06-17.