CVE-2018-5730

LOWCVSS 3.8/10EPSS 2.25%

Last modified

CVE-2018-5730 is a low-severity vulnerability rated 3.8/10 on the CVSS scale. MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.. EPSS estimates a 2.25% chance of exploitation in the next 30 days.

Description

MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

Metrics

CVSS 3.1
3.8/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

EPSS Probability
2.25%

80.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MitKerberos 5>= 5-1.6, < 5-1.21.2
FedoraprojectFedora26
FedoraprojectFedora27
DebianDebian Linux8.0
DebianDebian Linux9.0
RedhatEnterprise Linux Desktop7.0
RedhatEnterprise Linux Server7.0
RedhatEnterprise Linux Workstation7.0

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2018-5730?
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
How severe is CVE-2018-5730?
CVE-2018-5730 has a CVSS score of 3.8/10 (LOW severity). The EPSS model estimates a 2.25% probability of exploitation in the next 30 days.
How do I fix CVE-2018-5730?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-5730?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST