libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.
CVSS Details
- CVSS 3.1 Base Score: 4.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | Jul 14, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openldap-develUpgrade openldapUpgrade openldap-serversUpgrade openldap-clients | Aug 31, 2020 | Jul 14, 2020 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Jul 14, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 14, 2020 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.3.1Upgrade Splunk Enterprise to version 9.2.3Upgrade Splunk Enterprise to version 9.1.6 | Jul 30, 2026 | Jul 14, 2020 |
| Suse | — | Upgrade openldap2-contribUpgrade openldap2-ppolicy-check-passwordUpgrade openldap2-devel-32bitUpgrade libldap-dataUpgrade openldap2-develUpgrade libldap-2_4-2Upgrade openldap2-clientUpgrade openldap2Upgrade openldap2-back-sockUpgrade openldap2-back-sqlUpgrade openldap2-devel-staticUpgrade openldap2-back-metaUpgrade openldap2-docUpgrade libldap-2_4-2-32bitUpgrade openldap2-back-perl | Sep 13, 2020 | Jul 14, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub