Impact
Storing passwords with an excessively high bcrypt cost factor such as 30 in the Apache Directory LDAP API causes the server to spend extensive CPU cycles validating credentials. This excessive resource consumption can cause the LDAP server to become unresponsive for hours, effectively creating a denial‑of‑service condition. The weakness is a resource exhaustion flaw, classified as CWE‑405, and can compromise availability of the LDAP service.
Affected Systems
The vulnerable software is Apache Directory LDAP API version 2.1.0 through 2.1.8. Users running any of these releases are susceptible; versions 2.1.9 and later include the patch.
Risk and Exploitability
The vulnerability is high impact but the attack requires the ability to write or modify password entries in the LDAP directory, i.e., authentication and write access. The exact exploitation path is inferred from the description: an attacker with such access can set a high bcrypt cost factor and trigger the server’s excessive CPU usage. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, but its potential to cripple directory services warrants a high risk assessment. Immediate patching is advised.
OpenCVE Enrichment