libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openldap | — | Apply Apple macOS Security Update 2019-007 High SierraApply Apple macOS Security Update 2019-002 Mojave | Dec 11, 2019 | Dec 10, 2019 |
| Centos_linux | — | Upgrade openldapUpgrade openldap-serversUpgrade openldap-clientsUpgrade openldap-servers-sqlUpgrade openldap-devel | Dec 1, 2016 | Jun 16, 2012 |
| Gentoo Linux | — | Upgrade net-nds/openldap. | Oct 30, 2017 | Jun 16, 2012 |
| Oracle_linux | — | Upgrade openldap-develUpgrade openldap-servers-sqlUpgrade openldap-clientsUpgrade openldapUpgrade openldap-servers | Oct 16, 2024 | Jun 17, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub