An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
History
No history.
Information
Published : 2019-07-26 13:15
Updated : 2024-02-28 17:08
NVD link : CVE-2019-13057
Mitre link : CVE-2019-13057
CVE.ORG link : CVE-2019-13057
JSON object : View
Products Affected
apple
- mac_os_x
oracle
- blockchain_platform
- zfs_storage_appliance_kit
- solaris
canonical
- ubuntu_linux
opensuse
- leap
debian
- debian_linux
openldap
- openldap
mcafee
- policy_auditor
CWE