MEDIUM 4.3 Microsoft
CVE-2018-14628
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
Microsoft Security Update 2023-Jan: An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
Affected Products
- cbl2 samba 4.12.5-6 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-14628
- https://nvd.nist.gov/vuln/detail/CVE-2018-14628
This medium severity vulnerability with a CVSS score of 4.3 was published on 2023-01-10 via Microsoft. Affected: cbl2 samba 4.12.5-6 on CBL Mariner 2.0.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.