slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).
| Software | From | Fixed in |
|---|---|---|
| openldap / openldap | 2.0.22 | 2.0.22.x |
| openldap / openldap | 2.0.24 | 2.0.24.x |
| openldap / openldap | 2.0.20 | 2.0.20.x |
| openldap / openldap | 2.0.23 | 2.0.23.x |
| openldap / openldap | 2.0.21 | 2.0.21.x |