PT-2021-7948 · Microsoft+4 · System.Directoryservices.Protocols+4
Reno Robert
·
Published
2021-10-12
·
Updated
2025-09-04
·
CVE-2021-41355
CVSS v2.0
6.1
Medium
| Vector | AV:A/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
System.DirectoryServices.Protocols version 5.0.0
Description
A information disclosure issue exists where System.DirectoryServices.Protocols.LdapConnection may send credentials in plain text on Linux. This could allow a remote attacker to disclose protected information.
Recommendations
For System.DirectoryServices.Protocols version 5.0.0, update to version 5.0.1 to resolve the issue. As a temporary workaround, consider restricting the use of
System.DirectoryServices.Protocols on Linux systems until the update is applied. Avoid using the LdapConnection class in sensitive applications until the issue is resolved.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Red Hat
System.Directoryservices.Protocols