An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openldap | Openldap | * | 2.4.48 (excluding) |
Openldap | Ubuntu | bionic | * |
Openldap | Ubuntu | devel | * |
Openldap | Ubuntu | disco | * |
Openldap | Ubuntu | trusty | * |
Openldap | Ubuntu | trusty/esm | * |
Openldap | Ubuntu | upstream | * |
Openldap | Ubuntu | xenial | * |