An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
History
21 Nov 2024, 04:24
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html - Mailing List, Third Party Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html - Mailing List, Third Party Advisory | |
References | () http://seclists.org/fulldisclosure/2019/Dec/26 - Mailing List, Third Party Advisory | |
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10365 - Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2019/08/msg00024.html - Mailing List, Third Party Advisory | |
References | () https://seclists.org/bugtraq/2019/Dec/23 - Mailing List, Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20190822-0004/ - Third Party Advisory | |
References | () https://support.apple.com/kb/HT210788 - Third Party Advisory | |
References | () https://usn.ubuntu.com/4078-1/ - Third Party Advisory | |
References | () https://usn.ubuntu.com/4078-2/ - Third Party Advisory | |
References | () https://www.openldap.org/its/?findid=9038 - Mailing List, Vendor Advisory | |
References | () https://www.openldap.org/lists/openldap-announce/201907/msg00001.html - Mailing List, Product, Vendor Advisory | |
References | () https://www.oracle.com/security-alerts/cpuapr2020.html - Patch, Third Party Advisory | |
References | () https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory |
Information
Published : 2019-07-26 13:15
Updated : 2024-11-21 04:24
NVD link : CVE-2019-13057
Mitre link : CVE-2019-13057
CVE.ORG link : CVE-2019-13057
JSON object : View
Products Affected
debian
- debian_linux
oracle
- solaris
- blockchain_platform
- zfs_storage_appliance_kit
opensuse
- leap
openldap
- openldap
mcafee
- policy_auditor
canonical
- ubuntu_linux
apple
- mac_os_x
CWE