Improper Authorization in OpenLDAP - CVE-2019-13057

 

Improper Authorization in OpenLDAP - CVE-2019-13057

Published: July 30, 2019


Vulnerability identifier: #VU19561
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13057
CWE-ID: CWE-285
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to incorrect processing of rootDN delegation in the OpenLDAP multi-tenant deployments. A database administrator could use this issue to request authorization as an identity from another database, contrary to expectations.


Affected software

OpenLDAP
openldap (Alpine package)
Splunk Enterprise
Opensuse

How to mitigate CVE-2019-13057

Install updates from vendor's website.

OpenLDAP - update to 2.4.48
openldap (Alpine package) - addressed in versions 2.4.48-r0, 2.4.48-r2
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1

External References

Related Security Bulletins