VDB
KO
CRITICAL 9.6

GHSA-p279-2cqp-84jg

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

Quick fix

GHSA-p279-2cqp-84jg — org.openidentityplatform.opendj:opendj-server-legacy: upgrade to the fixed version with the command below.

# pom.xml: bump <version>5.1.2</version> for org.openidentityplatform.opendj:opendj-server-legacy

Details

### Summary When a SASL PLAIN bind supplies an authorization identity (authzid) that resolves to a **different** user, PlainSASLMechanismHandler verified only the PROXIED_AUTH privilege and never evaluated the "proxy" access-control right (the mayProxy ACI scope check). As a result, any account holding the proxied-auth privilege could assume **any resolvable non-root identity** without being granted a proxy ACI for that target.

This diverges from every other proxy path in OpenDJ — the proxied-authorization controls (RFC 4370) and the DIGEST-MD5 / GSSAPI authzid handlers all require **both** the privilege **and** the mayProxy scope grant.

### Impact Privilege escalation / authorization bypass: a holder of proxied-auth can act as arbitrary directory users beyond the scope intended by the deployment's proxy ACIs, defeating the ACI-based restriction on *which* identities may be impersonated. Root/Directory Manager is not assumable this way.

### Fix Enforce the mayProxy scope check on the SASL PLAIN authzid path (both dn: and u:/bare forms), sharing one hasProxyAccess helper with the DIGEST-MD5/GSSAPI path. Denial returns INVALID_CREDENTIALS (49) **before** password verification — matching DIGEST-MD5/GSSAPI — so an unauthenticated client cannot distinguish a missing privilege from a missing ACI grant.

### Workaround Restrict or revoke the proxied-auth privilege until upgraded.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / org.openidentityplatform.opendj:opendj-server-legacy
Introduced in: 0 Fixed in: 5.1.2
Fix # pom.xml: bump <version>5.1.2</version> for org.openidentityplatform.opendj:opendj-server-legacy

References