CVE-2022-0996 - User with expired password can still login with full privledges ...
authorMark Reynolds <mreynolds@redhat.com>
Thu, 3 Mar 2022 21:29:41 +0000 (16:29 -0500)
committerAndrej Shadura <andrewsh@debian.org>
Sun, 19 Jan 2025 12:30:31 +0000 (13:30 +0100)
commit4aa179339f804d46cdc899679f6ebb72318b8748
tree35ed68f4551f6c08e3a52f4dd6e3441106d81f3e
parent9e4defbd62eee152ac4dc520e1f0923add7ed18f
CVE-2022-0996 - User with expired password can still login with full privledges - Issue 5221

Bug Description:

A user with an expired password can still login and perform operations
with its typical access perimssions.  But an expired password means the
account should be considered anonymous.

Fix Description:

Clear the bind credentials if the password is expired

relates: https://github.com/389ds/389-ds-base/issues/5221

Reviewed by: progier(Thanks!)

Origin: upstream, commit:8b2c56123118ba02bb15e3091d2ae62d46df7ba5

Gbp-Pq: Name CVE-2022-0996-User-with-expired-password-full-priv.patch
dirsrvtests/tests/suites/password/pw_expired_access_test.py [new file with mode: 0644]
ldap/servers/slapd/pw_mgmt.c