PT-2022-6949 · Openldap2 · Openldap2

Matthias Gerstner

·

Published

2022-11-09

·

Updated

2022-11-10

·

CVE-2022-31253

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openldap2 versions prior to 2.6.3-404.1
Description The issue is related to an Untrusted Search Path vulnerability in openldap2, which allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root.
Recommendations For openldap2 versions prior to 2.6.3-404.1, update to version 2.6.3-404.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the ldap user or group to minimize the risk of exploitation.

Exploit

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2023-05706
CVE-2022-31253
OPENSUSE-SU-2024:12457-1

Affected Products

Openldap2