VDB
CVE-2019-13057
CVE-2019-13057
PUBLISHED
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
EPSS 0.57% · 69.0th percentile
Risk Scores
EPSS Score
0.57%
69.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:14.04:LTS | openldap | *, 0, 2.4.31-1+nmu2ubuntu8.5 |
| Ubuntu:16.04:LTS | openldap | 0, 2.4.41+dfsg-1ubuntu2, 2.4.42+dfsg-2ubuntu3 |
| Ubuntu:18.04:LTS | openldap | *, 2.4.45+dfsg-1ubuntu1.2, 2.4.45+dfsg-1ubuntu1 |
Exploit Intelligence
- CVE-2025-38062.yara (github-yara)
- CVE-2025-38062.yara (github-yara)
- CVE-2025-38062.yara (github-yara)
- CVE-2025-38062.yara (github-yara)
- CVE-2025-38062.yara (github-yara)
- CVE-2025-38062.yara (github-yara)
- CVE-2025-38062.yara (github-yara)
Timeline
- CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-13057 third-party-advisory
- https://www.openldap.org/lists/openldap-announce/201907/msg00001.html third-party-advisory
- https://ubuntu.com/security/notices/USN-4078-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-4078-2 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-13057 third-party-advisory