Описание
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.
Отчет
A Moderate impact flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an attacker able to reach a supplier's LDAP listener to remove a replica's entry from replication metadata, purge its changelog records, or interrupt an administrator's in-progress cleanup. Red Hat products with nsslapd-allow-anonymous-access enabled by default (the shipped default) allow this without any authentication; when that setting has been restricted, any authenticated account, regardless of privilege level, can still trigger the same behavior, since the affected operations do not perform an authorization check of their own.
Меры по смягчению последствий
Set nsslapd-allow-anonymous-access to rootdse or off as an interim mitigation. Note this only blocks exploitation by fully unauthenticated (unbound) clients; any connection that has completed a successful bind with any DN, including a low-privileged account, still reaches the vulnerable handlers with no further authorization check. Restrict replication LDAP ports to trusted networks as defense in depth pending a code fix.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Directory Server 11 | 389-ds-base | Fix deferred | ||
| Red Hat Directory Server 12 | 389-ds-base | Fix deferred | ||
| Red Hat Directory Server 13 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 10 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 6 | 389-ds-base | Out of support scope | ||
| Red Hat Enterprise Linux 7 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 8 | 389-ds-base | Fix deferred | ||
| Red Hat Enterprise Linux 9 | 389-ds-base | Fix deferred |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort Cl ...
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.
6.5 Medium
CVSS3