Executive brief
The Apache Groovy LDAP API, a tool used by developers to interact with directory services, contains a security flaw that allows for LDAP entry poisoning. An attacker could exploit this to manipulate directory data or potentially influence application logic that relies on these directory searches. This could lead to unauthorized changes in user information or system configurations.
Technical details
A vulnerability in the Apache Groovy LDAP API (specifically in main/java/org/apache/directory/groovyldap/LDAP.java) stems from the library automatically setting the 'returnObjFlag' to true for all LDAP search methods. This configuration instructs the underlying JNDI (Java Naming and Directory Interface) to return the Java object associated with an LDAP entry. An attacker who can control or influence LDAP entries can exploit this behavior to conduct LDAP entry poisoning. This can lead to the execution of arbitrary code or unauthorized data manipulation if the application deserializes or processes the returned objects without proper validation. The attack is reachable over the network without authentication if the application performs searches on attacker-influenced directory data.
Affected products
- Apache Software Foundation Groovy LDAP API
Timeline
- 2016-10-01: disclosed: Initial discussion on Apache mailing list
- 2017-01-18: advisory: NVD publication date
References
- http://svn.apache.org/viewvc/directory/sandbox/szoerner/groovyldap/src/main/java/org/apache/directory/groovyldap/LDAP.java?r1=1765362&r2=1765361&pathrev=1765362&view=patch
- http://www.securityfocus.com/bid/95929
- https://mail-archives.apache.org/mod_mbox/directory-users/201610.mbox/%3Cb7d7e909-a8ed-1ab4-c853-4078c1e7624a%40stefan-seelmann.de%3E
- https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html