CVE-2023-0225
Published Apr 3, 2023
Last updated a year ago
Overview
- Description
- A flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this attribute from any object in the directory.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity
- MEDIUM
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F914D5D-6211-4CF3-87AB-71284AD225A3", "versionEndExcluding": "4.17.7", "versionStartIncluding": "4.17.0" }, { "criteria": "cpe:2.3:a:samba:samba:4.18.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D9A6E955-CE26-405F-9468-4557A256CA8A" }, { "criteria": "cpe:2.3:a:samba:samba:4.18.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E9604B46-FDA2-4CA1-971F-315AFD250033" }, { "criteria": "cpe:2.3:a:samba:samba:4.18.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C209E4C-098B-4D49-A21B-AC8154FE3D85" }, { "criteria": "cpe:2.3:a:samba:samba:4.18.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2849132A-18B1-4A49-8B2E-8B6DCFCC0501" }, { "criteria": "cpe:2.3:a:samba:samba:4.18.0:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F657608C-18FB-49FA-A73E-F9BF5CD95B17" } ], "operator": "OR" } ] } ]