Описание
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
Отчет
This flaw affects any 389 Directory Server (or Red Hat Directory Server) deployment that defines an ACI using a userattr="attribute#SELFDN" or userattr="attribute#USERDN" bind rule on an attribute that is permitted to hold an explicit empty value. Red Hat Directory Server does not ship such an ACI by default; real-world impact depends on whether a specific deployment or consuming application defines an ACI of this shape.
Меры по смягчению последствий
Until a fix is available, review all ACIs using userattr="...#SELFDN" bind rules and confirm the target attribute cannot be set to an empty value, or add an explicit authmethod restriction to the ACI to prevent anonymous binds from satisfying the check. Where anonymous binds are not required, disabling anonymous access to the directory removes the attack surface entirely.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Directory Server 11 | 389-ds-base | Affected | ||
| Red Hat Directory Server 12 | 389-ds-base | Affected | ||
| Red Hat Directory Server 12 | redhat-ds:12/389-ds-base | Affected | ||
| Red Hat Directory Server 13 | 389-ds-base | Not affected | ||
| Red Hat Enterprise Linux 6 | 389-ds-base | Out of support scope | ||
| Red Hat Enterprise Linux 8 | 389-ds-base | Affected | ||
| Red Hat Directory Server 11.7 E4S for RHEL 8 | redhat-ds | Fixed | RHSA-2026:64792 | 08.09.2026 |
| Red Hat Directory Server 11.9 for RHEL 8 | redhat-ds | Fixed | RHSA-2026:64793 | 08.09.2026 |
| Red Hat Directory Server 12.2 E4S for RHEL 9 | redhat-ds | Fixed | RHSA-2026:64779 | 08.09.2026 |
| Red Hat Directory Server 12.4 E4S for RHEL 9 | redhat-ds | Fixed | RHSA-2026:64780 | 08.09.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule eva ...
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
EPSS
7.5 High
CVSS3