An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Information
Published : 2019-07-26 06:15
Updated : 2022-06-13 11:38
NVD link : CVE-2019-13057
Mitre link : CVE-2019-13057
JSON object : View
CWE
Products Affected
mcafee
- policy_auditor
openldap
- openldap
oracle
- blockchain_platform
- zfs_storage_appliance_kit
- solaris
canonical
- ubuntu_linux
opensuse
- leap
debian
- debian_linux
apple
- mac_os_x