CVE-2020-17477

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
26/10/2023
Last modified:
16/11/2023

Description

Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests. For example, a teacher can gain administrator access via an NTLM hash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:univention:ucs\@school:*:*:*:*:*:*:*:* 4.4 (including)


References to Advisories, Solutions, and Tools