CVE-2023-38994

The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks. By default, the configuration of UCS does not allow local ssh access for regular users.
Configurations

Configuration 1 (hide)

cpe:2.3:o:univention:univention_corporate_server:5.0:*:*:*:*:*:*:*

History

31 Jan 2024, 14:48

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-31 12:15

Updated : 2024-02-05 00:01


NVD link : CVE-2023-38994

Mitre link : CVE-2023-38994

CVE.ORG link : CVE-2023-38994


JSON object : View

Products Affected

univention

  • univention_corporate_server
CWE
CWE-668

Exposure of Resource to Wrong Sphere