CVE-2019-13057
26.07.2019, 13:15
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)Enginsight
| Vendor | Product | Version |
|---|---|---|
| openldap | openldap | 𝑥 < 2.4.48 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.04 |
| debian | debian_linux | 8.0 |
| opensuse | leap | 15.0 |
| opensuse | leap | 15.1 |
| apple | mac_os_x | 10.13 ≤ 𝑥 < 10.13.6 |
| apple | mac_os_x | 10.14 ≤ 𝑥 < 10.14.6 |
| apple | mac_os_x | 10.15 ≤ 𝑥 < 10.15.2 |
| apple | mac_os_x | 10.13.6 |
| apple | mac_os_x | 10.13.6:security_update_2018-002 |
| apple | mac_os_x | 10.13.6:security_update_2018-003 |
| apple | mac_os_x | 10.13.6:security_update_2019-001 |
| apple | mac_os_x | 10.13.6:security_update_2019-002 |
| apple | mac_os_x | 10.13.6:security_update_2019-003 |
| apple | mac_os_x | 10.13.6:security_update_2019-004 |
| apple | mac_os_x | 10.13.6:security_update_2019-005 |
| apple | mac_os_x | 10.13.6:security_update_2019-006 |
| apple | mac_os_x | 10.14.6 |
| apple | mac_os_x | 10.14.6 |
| apple | mac_os_x | 10.14.6:security_update_2019-001 |
| mcafee | policy_auditor | 𝑥 < 6.5.1 |
| mcafee | policy_auditor | 6.5.1 |
| oracle | blockchain_platform | 𝑥 < 21.1.2 |
| oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References