bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openldap | Jul 30, 2024 | Mar 20, 2011 |
| Gentoo Linux | — | Upgrade net-nds/openldap. | Oct 30, 2017 | Mar 19, 2011 |
| Oracle_linux | — | Upgrade openldap-clientsUpgrade openldap-servers-sqlUpgrade openldap-develUpgrade openldapUpgrade compat-openldapUpgrade openldap-servers | Oct 16, 2024 | Mar 20, 2011 |
| Ubuntu | — | Upgrade slapd | Nov 8, 2024 | Mar 20, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub