CVE-2017-7551: Fedoraproject 389 Directory Server
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
Affected products
- Fedoraproject 389 Directory Server: version 1.3.5.19 only; version 1.3.6.7 only
Published 2017-08-16. Last modified 2026-06-17.