CVE-2019-13057: Medium severity Apple macOS Catalina vulnerability
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
Other sources
OpenLDAP. Multiple issues were addressed by updating to OpenLDAP version 2.4.28.
Credit
Affected Software
Remediation
Patch Available
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8837
- CVE-2019-8853
- CVE-2019-8856
- CVE-2019-8848
- CVE-2019-8834
- CVE-2019-8842
- CVE-2019-8839
- CVE-2019-8830
- CVE-2019-8851
- CVE-2019-8833
- CVE-2019-8828
- CVE-2019-8838
- CVE-2019-8847
- CVE-2019-8852
- CVE-2019-15903
- CVE-2020-9782
- CVE-2012-1164
- CVE-2012-2668
- CVE-2013-4449
- CVE-2015-1545
- CVE-2019-13057
- CVE-2019-13565
- CVE-2019-8832
- CVE-2017-16808
- CVE-2018-10103
- CVE-2018-10105
- CVE-2018-14461
- CVE-2018-14462
- CVE-2018-14463
- CVE-2018-14464
- CVE-2018-14465
- CVE-2018-14466
- CVE-2018-14467
- CVE-2018-14468
- CVE-2018-14469
- CVE-2018-14470
- CVE-2018-14879
- CVE-2018-14880
- CVE-2018-14881
- CVE-2018-14882
- CVE-2018-16227
- CVE-2018-16228
- CVE-2018-16229
- CVE-2018-16230
- CVE-2018-16300
- CVE-2018-16301
- CVE-2018-16451
- CVE-2018-16452
- CVE-2019-15166
- CVE-2019-15167
- CVE-2019-15126
Frequently Asked Questions
What is CVE-2019-13057?
CVE-2019-13057 is a vulnerability in OpenLDAP that was addressed in version 2.4.28.
How does CVE-2019-13057 affect macOS Catalina?
macOS Catalina 10.15.2 is affected by CVE-2019-13057, but updating to version 2.4.28 of OpenLDAP resolves the issue.
Is Mojave affected by CVE-2019-13057?
Yes, macOS Mojave is affected by CVE-2019-13057, and updating OpenLDAP to version 2.4.28 is recommended.
What about High Sierra? Is it affected by CVE-2019-13057?
Yes, macOS High Sierra is also affected by CVE-2019-13057, and updating OpenLDAP to version 2.4.28 is recommended.
Where can I find more information about CVE-2019-13057?
You can find more information about CVE-2019-13057 at the following reference: [Apple Support](https://support.apple.com/en-us/HT210788)