Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13057

Опубликовано: 25 июл. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

Отчет

This issue affects the versions of openldap-server as shipped with Red Hat Enterprise Linux (RHEL) 5, 6, 7. Starting in RHEL 8 the openldap-server is not delivered anymore, therefore RHEL 8 is not affected by this vulnerability. This vulnerability does not affect the RHEL openldap package, what contains configuration files, libraries, and documentation for OpenLDAP. Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Меры по смягчению последствий

This is only an issue in e.g. multi-tenant deployments that require isolation of databases. Do not give rootDN privileges to untrusted users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openldapOut of support scope
Red Hat Enterprise Linux 6compat-openldapNot affected
Red Hat Enterprise Linux 6openldapOut of support scope
Red Hat Enterprise Linux 7compat-openldapNot affected
Red Hat Enterprise Linux 7openldapWill not fix
Red Hat Enterprise Linux 8openldapNot affected
Red Hat JBoss Core ServicesopenldapOut of support scope
Red Hat JBoss Enterprise Application Platform 5openldapOut of support scope
Red Hat JBoss Enterprise Web Server 2openldapOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1730472openldap: Information disclosure issue in slapd component

EPSS

Процентиль: 68%
0.00582
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
nvd
больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
debian
больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When ...

CVSS3: 4.9
github
больше 3 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость демона slapd пакета OpenLDAP, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 68%
0.00582
Низкий

6.5 Medium

CVSS3