{"id":"GHSA-p279-2cqp-84jg","title":"OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check","summary":"OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check","severity":"critical","cvss":9.6,"cwe":["CWE-285","CWE-639"],"vendor":"openidentityplatform","product":"org.openidentityplatform.opendj:opendj-server-legacy","ecosystem":"maven","affected":["org.openidentityplatform.opendj:opendj-server-legacy <= 5.1.1"],"patched":["org.openidentityplatform.opendj:opendj-server-legacy 5.1.2"],"published":"2026-07-24","updated":"2026-07-24","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-p279-2cqp-84jg","references":[{"url":"https://github.com/OpenIdentityPlatform/OpenDJ/security/advisories/GHSA-p279-2cqp-84jg"},{"url":"https://github.com/OpenIdentityPlatform/OpenDJ/commit/5c326850f1ab945cfca7ac9c5aaf77d1052c6bed"},{"url":"https://github.com/OpenIdentityPlatform/OpenDJ/releases/tag/5.1.2"},{"url":"https://github.com/advisories/GHSA-p279-2cqp-84jg"}],"tags":["ghsa","maven"],"ingestedAt":"2026-07-24T22:40:27.130Z","slug":"GHSA-p279-2cqp-84jg","body":"## Overview\n\n### Summary\nWhen a SASL PLAIN bind supplies an authorization identity (authzid) that resolves to a **different** user, PlainSASLMechanismHandler verified only the PROXIED_AUTH privilege and never evaluated the \"proxy\" access-control right (the mayProxy ACI scope check). As a result, any account holding the proxied-auth privilege could assume **any resolvable non-root identity** without being granted a proxy ACI for that target.\n\nThis diverges from every other proxy path in OpenDJ — the proxied-authorization controls (RFC 4370) and the DIGEST-MD5 / GSSAPI authzid handlers all require **both** the privilege **and** the mayProxy scope grant.\n\n### Impact\nPrivilege escalation / authorization bypass: a holder of proxied-auth can act as arbitrary directory users beyond the scope intended by the deployment's proxy ACIs, defeating the ACI-based restriction on *which* identities may be impersonated. Root/Directory Manager is not assumable this way.\n\n### Fix\nEnforce the mayProxy scope check on the SASL PLAIN authzid path (both dn: and u:/bare forms), sharing one hasProxyAccess helper with the DIGEST-MD5/GSSAPI path. Denial returns INVALID_CREDENTIALS (49) **before** password verification — matching DIGEST-MD5/GSSAPI — so an unauthenticated client cannot distinguish a missing privilege from a missing ACI grant.\n\n### Workaround\nRestrict or revoke the proxied-auth privilege until upgraded.\n\n## Affected packages\n\n- `org.openidentityplatform.opendj:opendj-server-legacy <= 5.1.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `org.openidentityplatform.opendj:opendj-server-legacy 5.1.2`","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":52.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}