CVE-2020-35518: Red Hat 389 Directory Server
Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Affected products
- Red Hat 389 Directory Server: before 1.4.3.19 (fixed in 1.4.3.19); from 1.4.4.0, before 1.4.4.13 (fixed in 1.4.4.13); from 2.0.0, before 2.0.3 (fixed in 2.0.3)
- Red Hat Directory Server: version 11.0 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
Published 2021-03-26. Last modified 2026-06-17.