MIT krb5 1.6 or later allows an authenticated kadmin with...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated May 23, 2024
Description
Published by the National Vulnerability Database
Mar 6, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
May 23, 2024
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
References