openldap: Information disclosure issue in slapd component
Published Jul 26, 2019
4.9
MEDIUMCVSS 3.1
EPSS 3.42%
Description
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
Affected products
No data.
Configuration 2
- 12.04
- 14.04
- 16.04
- 18.04
- 19.04
Configuration 3
- 8.0
Configuration 5
- ≥ 10.13 · < 10.13.6
- ≥ 10.14 · < 10.14.6
- ≥ 10.15 · < 10.15.2
- 10.13.6
- 10.13.6
- 10.13.6
- 10.13.6
- 10.13.6
- 10.13.6
- 10.13.6
- 10.13.6
- 10.13.6
- 10.14.6
- 10.14.6
- 10.14.6
Configuration 6
- < 6.5.1
- 6.5.1
Configuration 7
- < 21.1.2
- 8.8
- 11
No data.
Red Hat Enterprise Linux 5
openldap
Out of support scope
Red Hat Enterprise Linux 6
compat-openldap
Not affected
Red Hat Enterprise Linux 6
openldap
Out of support scope
Red Hat Enterprise Linux 7
compat-openldap
Not affected
Red Hat Enterprise Linux 7
openldap
Will not fix
Red Hat Enterprise Linux 8
openldap
Not affected
Red Hat JBoss Core Services
openldap
Out of support scope
Red Hat JBoss Enterprise Application Platform 5
openldap
Out of support scope
Red Hat JBoss Enterprise Web Server 2
openldap
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openldap | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | compat-openldap | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openldap | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | compat-openldap | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openldap | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | openldap | Not affected | n/a |
| Red Hat JBoss Core Services | openldap | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openldap | Out of support scope | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openldap | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of openldap-server as shipped with Red Hat Enterprise Linux (RHEL) 5, 6, 7. Starting in RHEL 8 the openldap-server is not delivered anymore, therefore RHEL 8 is not affected by this vulnerability. This vulnerability does not affect the RHEL openldap package, what contains configuration files, libraries, and documentation for OpenLDAP. Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Red Hat mitigation
This is only an issue in e.g. multi-tenant deployments that require isolation of databases. Do not give rootDN privileges to untrusted users.
References (21)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/26 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://www.openldap.org/lists/openldap-announce/201907/msg00001.html
- https://access.redhat.com/security/cve/CVE-2019-13057 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1730472 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-4617 Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10365 x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00024.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-13057
- https://openldap.org/its/?findid=9038
- https://seclists.org/bugtraq/2019/Dec/23 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190822-0004/ x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT210788 x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4078-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4078-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-13057
- https://www.openldap.org/its/?findid=9038 x_refsource_MISCMailing ListVendor Advisory
- https://www.openldap.org/lists/openldap-announce/201907/msg00001.html x_refsource_CONFIRMMailing ListProductVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data