CVE Vulnerabilities

CVE-2014-0132

Improper Authentication

Published: Mar 18, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
389_directory_serverFedoraproject*1.2.11.25 (including)
389_directory_serverFedoraproject1.2.11.1 (including)1.2.11.1 (including)
389_directory_serverFedoraproject1.2.11.5 (including)1.2.11.5 (including)
389_directory_serverFedoraproject1.2.11.6 (including)1.2.11.6 (including)
389_directory_serverFedoraproject1.2.11.8 (including)1.2.11.8 (including)
389_directory_serverFedoraproject1.2.11.9 (including)1.2.11.9 (including)
389_directory_serverFedoraproject1.2.11.10 (including)1.2.11.10 (including)
389_directory_serverFedoraproject1.2.11.11 (including)1.2.11.11 (including)
389_directory_serverFedoraproject1.2.11.12 (including)1.2.11.12 (including)
389_directory_serverFedoraproject1.2.11.13 (including)1.2.11.13 (including)
389_directory_serverFedoraproject1.2.11.14 (including)1.2.11.14 (including)
389_directory_serverFedoraproject1.2.11.15 (including)1.2.11.15 (including)
389_directory_serverFedoraproject1.2.11.17 (including)1.2.11.17 (including)
389_directory_serverFedoraproject1.2.11.19 (including)1.2.11.19 (including)
389_directory_serverFedoraproject1.2.11.20 (including)1.2.11.20 (including)
389_directory_serverFedoraproject1.2.11.21 (including)1.2.11.21 (including)
389_directory_serverFedoraproject1.2.11.22 (including)1.2.11.22 (including)
389_directory_serverFedoraproject1.2.11.23 (including)1.2.11.23 (including)
Red Hat Enterprise Linux 6RedHat389-ds-base-0:1.2.11.15-32.el6_5*
389-ds-baseUbuntuprecise*
389-ds-baseUbuntuquantal*
389-ds-baseUbuntusaucy*
389-ds-baseUbuntuupstream*

Potential Mitigations

References