Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24633
HistoryApr 10, 2020 - 12:59 a.m.

Authentication Bypass

2020-04-1000:59:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.004

Percentile

74.0%

openldap is vulnerable to authentication bypass. The vulnerability exists as a flaw was found in the way OpenLDAP handled authentication failures being passed from an OpenLDAP slave to the master. If OpenLDAP was configured with a chain overlay and it forwarded authentication failures, OpenLDAP would bind to the directory as an anonymous user and return success, rather than return failure on the authenticated bind. This could allow a user on a system that uses LDAP for authentication to log into a directory-based account without knowing the password.

References