Vulnerability Description
Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests. For example, a teacher can gain administrator access via an NTLM hash.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Univention | Ucs\@School | <= 4.4 |
Related Weaknesses (CWE)
References
- https://forge.univention.org/bugzilla/show_bug.cgi?id=50669Issue TrackingThird Party Advisory
- https://forge.univention.org/bugzilla/show_bug.cgi?id=50669Issue TrackingThird Party Advisory
FAQ
What is CVE-2020-17477?
CVE-2020-17477 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sam...
How severe is CVE-2020-17477?
CVE-2020-17477 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-17477?
Check the references section above for vendor advisories and patch information. Affected products include: Univention Ucs\@School.