Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2011-1024

chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

  • Published: Mar 20, 2011
  • Updated: Apr 13, 2023
  • CVE: CVE-2011-1024
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.6
  • AV:N/AC:H/Au:S/C:P/I:P/A:P

CWEs:

Software From Fixed in
openldap / openldap 2.4.17 2.4.17.x
openldap / openldap 2.4.6 2.4.6.x
openldap / openldap 2.4.11 2.4.11.x
openldap / openldap 2.4.8 2.4.8.x
openldap / openldap 2.4.9 2.4.9.x
openldap / openldap 2.4.16 2.4.16.x
openldap / openldap 2.4.22 2.4.22.x
openldap / openldap 2.4.20 2.4.20.x
openldap / openldap 2.4.15 2.4.15.x
openldap / openldap 2.4.18 2.4.18.x
openldap / openldap 2.4.7 2.4.7.x
openldap / openldap 2.4.23 2.4.23.x
openldap / openldap 2.4.14 2.4.14.x
openldap / openldap 2.4.19 2.4.19.x
openldap / openldap 2.4.12 2.4.12.x
openldap / openldap 2.4.21 2.4.21.x
openldap / openldap 2.4.13 2.4.13.x
openldap / openldap 2.4.10 2.4.10.x