Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenLDAP back-ndb bind.cpp访问限制绕过漏洞
Vulnerability Description
OpenLDAP是美国OpenLDAP基金会的一个轻型目录访问协议(LDAP)的自由和开源实现,它已被包含在Linux发行版中。 OpenLDAP的back-ndb组件中的bind.cpp在处理“rootdn”的认证请求时存在错误。远程攻击者可以借助任意密码绕过预设的访问限制。该漏洞影响OpenLDAP 2.4.24之前的2.4.x版本。
CVSS Information
N/A
Vulnerability Type
N/A