An issue was discovered in the server in OpenLDAP before...
Vulnerability Description
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13057
Credits & Attribution
No credits recorded in the NVD database.
References
- https://usn.ubuntu.com/4078-1/
- https://lists.debian.org/debian-lts-announce/2019/08/msg00024.html
- https://usn.ubuntu.com/4078-2/
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html
- https://seclists.org/bugtraq/2019/Dec/23
- http://seclists.org/fulldisclosure/2019/Dec/26
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://support.apple.com/kb/HT210788
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365
- https://www.openldap.org/its/?findid=9038
- https://www.openldap.org/lists/openldap-announce/201907/msg00001.html
- https://security.netapp.com/advisory/ntap-20190822-0004/
More from openldap
View All →Affected Vendor
openldap
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.