#ldap

2 posts · Last used 16d

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 29, 2026
Four OpenDJ vulnerabilities are patched in 5.1.2. They include a CVSS 9.6 authorization bypass and an unauthenticated SSRF scoring CVSS 9.4. #OpenDJ #SSRF #LDAP #AuthorizationBypass https://securityonline.info/opendj-vulnerabilities-5-1-2/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Jesus Michał von Gentoo 🏔 (he) @mgorny@social.treehouse.systems · Jul 13, 2026
Zero days since 83 #Gentoo developers effectively lost push access over revoked PGP key signatures because of random #LDAP hiccup. Yes, we have error handling. And yes, we have a safety check in case error handling didn't work and LDAP returned empty list of developers. Yet apparently that's not enough either, so now we also check if the diff between old and new lists isn't too large; you know, in case ldapsearch randomly returned a subset of developers and considered it a success.
0
0
0

You've seen all posts