CVE-2019-14824: Debian Linux

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fedoraproject 389 Directory Server: affected versions not specified
  • Red Hat Enterprise Linux: version 7.0 only

Published 2019-11-08. Last modified 2026-06-17.