{"id":"CVE-2019-14824","details":"A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.","modified":"2026-03-15T22:29:33.508218Z","published":"2019-11-08T15:15:11.563Z","related":["MGASA-2019-0411","openSUSE-SU-2024:10593-1"],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00026.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3981"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0464"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/11/msg00036.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14824"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14824.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}