Description
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1891-1 | openldap security update |
EUVD |
EUVD-2019-4617 | An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.) |
Ubuntu USN |
USN-4078-1 | OpenLDAP vulnerabilities |
Ubuntu USN |
USN-4078-2 | OpenLDAP vulnerabilities |
References
History
No history.
Subscriptions
Apple
Subscribe
Mac Os X
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Mcafee
Subscribe
Policy Auditor
Subscribe
Openldap
Subscribe
Openldap
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Oracle
Subscribe
Blockchain Platform
Subscribe
Solaris
Subscribe
Zfs Storage Appliance Kit
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:41:10.083Z
Reserved: 2019-06-29T00:00:00.000Z
Link: CVE-2019-13057
No data.
Status : Modified
Published: 2019-07-26T13:15:12.317
Modified: 2024-11-21T04:24:07.423
Link: CVE-2019-13057
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN