When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35518.json"
[
{
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"156327268525253698363660899521115683274",
"335402869101960669245776613554960002091",
"48679503366445529733574487735975941163",
"55275383875053882883620881562959351365",
"97793999284390048575770039265417524602",
"93437357065529380144791841150808323560",
"334210813283020886431060458429448003454",
"295683751000731501741412729082515590555",
"200895548605128804941227070130969920888",
"114568757203904273824644200368920260210",
"283960780581346130140347495791233769035",
"154052428143839224908335269617999166533"
]
},
"signature_type": "Line",
"target": {
"file": "ldap/servers/slapd/dse.c"
},
"source": "https://github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32",
"id": "CVE-2020-35518-6668af7b",
"signature_version": "v1"
},
{
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"231900200210085628883299799942067668579",
"293227023537761690832979670014535727304",
"529580841501224453670901892392782820",
"92938755121922726516016927907363779926",
"119176856061870748709409521201365395736"
]
},
"signature_type": "Line",
"target": {
"file": "ldap/servers/slapd/back-ldbm/ldbm_bind.c"
},
"source": "https://github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32",
"id": "CVE-2020-35518-6dbc738f",
"signature_version": "v1"
},
{
"deprecated": false,
"digest": {
"function_hash": "121539299605689041318853093154430367139",
"length": 2174.0
},
"signature_type": "Function",
"target": {
"file": "ldap/servers/slapd/back-ldbm/ldbm_bind.c",
"function": "ldbm_back_bind"
},
"source": "https://github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32",
"id": "CVE-2020-35518-ae816c87",
"signature_version": "v1"
},
{
"deprecated": false,
"digest": {
"function_hash": "156790754977640553600549957926651256104",
"length": 1488.0
},
"signature_type": "Function",
"target": {
"file": "ldap/servers/slapd/dse.c",
"function": "dse_bind"
},
"source": "https://github.com/389ds/389-ds-base/commit/b6aae4d8e7c8a6ddd21646f94fef1bf7f22c3f32",
"id": "CVE-2020-35518-f7fbbd76",
"signature_version": "v1"
}
]