Back

MEDIUM

openldap: Information disclosure issue in slapd component

Published Jul 26, 2019

Description

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

Affected products

Remediation

Red Hat statement

This issue affects the versions of openldap-server as shipped with Red Hat Enterprise Linux (RHEL) 5, 6, 7. Starting in RHEL 8 the openldap-server is not delivered anymore, therefore RHEL 8 is not affected by this vulnerability. This vulnerability does not affect the RHEL openldap package, what contains configuration files, libraries, and documentation for OpenLDAP. Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Red Hat mitigation

This is only an issue in e.g. multi-tenant deployments that require isolation of databases. Do not give rootDN privileges to untrusted users.

References (21)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Jul 26, 2019
Updated Aug 4, 2024
Reserved Jun 29, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jul 25, 2019
Bugzilla 1730472

ENISA EUVD

Assigner mitre
Published Jul 26, 2019
Updated Aug 4, 2024

GitHub

No data