Back

MEDIUM

openldap: forwarded bind failure messages cause success

Published Mar 20, 2011

Description

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 20, 2011
Updated Aug 6, 2024
Reserved Feb 14, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jul 28, 2010