Port389 maintains the 389 Directory Server, a widely deployed open-source LDAP directory implementation used in enterprise authentication and identity-management infrastructures. The sparse vulnerability record reflects issues centered on memory-safety flaws such as double-free and NULL-pointer dereference conditions, alongside authentication and access-control weaknesses characteristic of directory-service protocols; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Port389 over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4091HIGH A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to | Feb 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-2850MEDIUM A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. Thi | Oct 14, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-3652MEDIUM A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully m | Apr 18, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-0918HIGH A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of | Mar 16, 2022 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Port389.
Media articles that mention a CVE ID that affects a product developed by Port389 — matched by CVE ID, not by vendor name.