Loading HuntDB...

GHSA-282x-mj8h-7q8w

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

Related CVEs

Key Information

GHSA ID
GHSA-282x-mj8h-7q8w
Published
May 24, 2022 4:51 PM
Last Modified
April 4, 2024 1:25 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.