suse · CVE-2022-2850

Quick triage

Priority: medium Published: 2022-08-19 23:43:03 UTC Updated: 2026-03-05 04:54:11 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2022-2850 severity moderate: SUSE including 40 source package names (2.0-16.28:389-ds-2.0.16~git20.219f047ae-150400.3.10.1, 2.0-16.28:lib389-2.0.16~git20.219f047ae-150400.3.10.1, …), 105 product×package rows across 31 product lines (Container suse/389-ds, SUSE CaaS Platform 4.0, … (31 product lines)): Known Not Affected 58, Fixed 47.

Description:

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.

cvelogic Threat Intelligence