CVE-2020-15719
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-15719 affects the libldap component in certain third-party OpenLDAP packages, specifically when the package is asserting RFC6125 support. The vulnerability was discovered in July 2020 and affects various versions of OpenLDAP packages across different distributions (CVE Details).

Technical details

The vulnerability involves a certificate-validation flaw where the system considers CN (Common Name) even when there is a non-matching subjectAltName (SAN). This behavior conflicts with certificate validation standards, particularly in the context of RFC6125 support. The issue was fixed in openldap-2.4.46-10.el8 in Red Hat Enterprise Linux (Debian Tracker).

Impact

The vulnerability could lead to incorrect certificate validation, potentially allowing connections to be established with servers using certificates that should be considered invalid. This could affect the security of TLS connections using affected OpenLDAP implementations (OpenLDAP Bug).

Mitigation and workarounds

The issue has been fixed in openldap-2.4.46-10.el8 for Red Hat Enterprise Linux. Various distributions have released patches, including OpenSUSE through security updates 2020:1416 and 2020:1459. Organizations should update to the patched versions of OpenLDAP packages (SUSE Security).

Community reactions

There has been some debate in the security community about the validity of this vulnerability. OpenLDAP upstream disputed the issue, stating that the current libldap behavior conforms with RFC4513, and RFC6125 does not supersede the rules for verifying service identity provided in specifications for existing application protocols (OpenLDAP Bug).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management