Executive brief
OpenDJ is a directory server used to manage and store user identities and access permissions. A vulnerability in its authentication process allows a user with basic 'proxied-auth' permissions to impersonate almost any other user in the system, bypassing intended security restrictions. This could allow an attacker to gain unauthorized access to sensitive data or perform actions on behalf of other employees, though administrative 'root' accounts are not affected.
Technical details
A vulnerability exists in the PlainSASLMechanismHandler of OpenDJ where the 'mayProxy' ACI scope check is not evaluated during SASL PLAIN binds that use an authorization identity (authzid). While the handler verifies the PROXIED_AUTH privilege, it fails to enforce the access-control rights that restrict which specific identities a user is permitted to assume. An attacker with the proxied-auth privilege can bypass ACI-based restrictions to impersonate any resolvable non-root identity. This issue is specific to the SASL PLAIN path and does not affect DIGEST-MD5 or GSSAPI handlers. The vulnerability is fixed in version 5.1.2 by enforcing the mayProxy scope check.
Affected products
- OpenIdentityPlatform OpenDJ <= 5.1.1
Timeline
- 2026-07-23: disclosed
- 2026-07-24: advisory: GitHub Advisory GHSA-p279-2cqp-84jg published
- 2026-07-24: patched: Version 5.1.2 released