Bug 1730472 (CVE-2019-13057)

Summary: CVE-2019-13057 openldap: Information disclosure issue in slapd component
Product: [Other] Security Response Reporter: Pedro Sampaio <psampaio>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: asoldano, bbaranow, bmaxwell, brian.stansberry, cdewolf, chazlett, csutherl, darran.lofthouse, dosoudil, gzaronik, iweiss, jawilson, jclere, jperkins, krathod, kwills, lgao, mbabacek, msochure, msvehla, mturk, myarboro, nwallace, pkis, pmackay, psotirop, rguimara, rmeggins, rsvoboda, scorneli, security-response-team, smaestri, spichugi, tom.jenkinson, twalsh, vashirov, weli
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: openldap 2.4.48 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-12-10 16:15:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1734760, 1738925, 1740757    
Bug Blocks: 1730478    

Description Pedro Sampaio 2019-07-16 19:57:52 UTC
A flaw was found in openldap before version 2.4.48. A rootdn for database A can incorrectly assert the identity of any user in database B.

References:

https://bugzilla.redhat.com/show_bug.cgi?id=1728902

Comment 1 Marian Rehak 2019-07-31 11:21:23 UTC
Created openldap tracking bugs for this issue:

Affects: fedora-all [bug 1734760]

Comment 2 Joshua Padman 2019-08-06 05:33:23 UTC
This vulnerability is out of security support scope for the following product:
 * Red Hat Enterprise Application Platform 5
 * Red Hat JBoss Web Server 2 
 * Red Hat JBoss Core Services

Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.

Comment 6 Stefan Cornelius 2019-08-08 12:01:56 UTC
Mitigation:

This is only an issue in e.g. multi-tenant deployments that require isolation of databases. Do not give rootDN privileges to untrusted users.

Comment 9 Stefan Cornelius 2019-08-14 16:35:22 UTC
Statement:

This issue affects the versions of openldap as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8.

Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.