blob: 9b726a4b1725573ab5af699af3bde117ea5ca7a7 [file]
---
layout: post
status: PUBLISHED
published: true
title: "[CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds"
id: a7282388-70ae-469b-ae71-8f6af0b2966e
date: '2014-12-08 20:11:09 -0500'
categories: cloudstack
tags: []
permalink: cloudstack/entry/cve_2014_7807_apache_cloudstack
---
<p>CVE-2014-7807: Apache CloudStack unauthenticated LDAP binds</p>
<p>CVSS:<br><br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P</p>
<p>Vendors:<br><br />
The Apache Software Foundation<br><br />
Citrix, Inc.</p>
<p>Versions Afffected:<br><br />
Apache CloudStack 4.3, 4.4</p>
<p>Description:<br><br />
Apache CloudStack may be configured to authenticate LDAP users.<br />
When so configured, it performs a simple LDAP bind with the name<br />
and password provided by a user. Simple LDAP binds are defined<br />
with three mechanisms (RFC 4513): 1) username and password; 2)<br />
unauthenticated if only a username is specified; and 3) anonymous<br />
if neither username or password is specified. Currently, Apache<br />
CloudStack does not check if the password was provided which could<br />
allow an attacker to bind as an unauthenticated user.</p>
<p>Mitigation:<br><br />
Users of Apache CloudStack 4.4 and derivatives should update to the<br />
latest version (4.4.2)</p>
<p>An updated release for Apache CloudStack 4.3.2 is in testing. Until<br />
that is released, we recommend following the mitigation below:</p>
<p>By default, many LDAP servers are not configured to allow unauthenticated<br />
binds. If the LDAP server in use allow this behaviour, a potential<br />
interim solution would be to consider disabling unauthenticated<br />
binds.</p>
<p>Credit:<br><br />
This issue was identified by the Citrix Security Team.</p>