Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

github логотип

GHSA-5x95-66xj-7chm

больше 4 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2019-13057

около 7 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2019-13057

около 7 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-13057

около 7 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2019-13057

около 7 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When ...

CVSS3: 4.9
EPSS: Низкий
fstec логотип

BDU:2019-04729

около 7 лет назад

Уязвимость демона slapd пакета OpenLDAP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14353-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2390-1

почти 7 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2176-1

почти 7 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2157-1

почти 7 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1210-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2395-1

почти 7 лет назад

Security update for openldap2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5x95-66xj-7chm

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
3%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
3%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 6.5
3%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
3%
Низкий
около 7 лет назад
debian логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When ...

CVSS3: 4.9
3%
Низкий
около 7 лет назад
fstec логотип
BDU:2019-04729

Уязвимость демона slapd пакета OpenLDAP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
3%
Низкий
около 7 лет назад
suse-cvrf логотип
SUSE-SU-2020:14353-1

Security update for openldap2

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2390-1

Security update for openldap2

почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2176-1

Security update for openldap2

почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2157-1

Security update for openldap2

почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2020:1210-1

Security update for openldap2

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2395-1

Security update for openldap2

почти 7 лет назад

Уязвимостей на страницу