Back

HIGH

openldap: ACL restrictions bypass due to sasl_ssf value being set permanently

Published Jul 26, 2019

Description

An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is retained for all new non-SASL connections. Depending on the ACL configuration, this can affect different types of operations (searches, modifications, etc.). In other words, a successful authorization step completed by one user affects the authorization requirement for a different user.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of openldap as shipped with Red Hat Enterprise Linux 8, as it only affects the openldap-servers package, which is not shipped.

Weaknesses (1)

References (22)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 26, 2019
Updated Aug 4, 2024
Reserved Jul 11, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 24, 2019