
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-8027 affects OpenLDAP2's openldap_update_modules_path.sh script, which was discovered to have critical security issues. The vulnerability was reported on August 20, 2020, and affects SUSE Linux Enterprise products. The script had multiple security issues related to insecure file handling and daemon management (SUSE Bugzilla).
The vulnerability stems from two main issues in the openldap_update_modules_path.sh script: 1) The script uses fixed paths in /tmp without checking if they already exist, potentially allowing overwriting of system files, and 2) It unconditionally starts the slapd daemon during updates, even if it wasn't previously running. The script uses fixed paths for tmp_file='/tmp/ldap_conf_tmp.ldif' and backup='/tmp/slapd.d' without proper error handling (SUSE Bugzilla).
The vulnerability could lead to multiple security issues including: 1) DoS attacks through symlink following, 2) Unauthorized access to configuration files normally restricted, 3) Complete compromise of slapd configuration through attacker-controlled files, and 4) Service disruption due to unconditional daemon management (SUSE Bugzilla).
The vulnerability can be exploited locally through multiple attack vectors including symlink attacks and manipulation of temporary files. The attack requires local access to the system (SUSE Bugzilla).
The issue was fixed in SUSE Linux Enterprise through security updates (SUSE-SU-2020:2712-1 and SUSE-SU-2020:2712-2). The fix involved replacing the original script with new scripts that properly handle temporary files using mktemp and implement proper service management (SUSE Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."