github osixia/docker-openldap v1.2.1

latest releases: v1.5.0, v1.4.0, v1.3.0...
5 years ago

Security

  • The default "write" access to "*" by "self" in the file "config/bootstrap/ldif/02-security.ldif" allowed anyone to change all the data about himself. This includes the gid and uid numbers what could lead to serious security issues.

This has been changed to olcAccess: to * by self read by dn="cn=admin,{{ LDAP_BASE_DN }}" write by * none"

Thanks to Francesc Escale for reporting this.

Don't miss a new docker-openldap release

NewReleases is sending notifications on new releases.