CyberRota Analysis
AI-GeneratedA vulnerability in 389 Directory Server allows unauthenticated remote attackers, or authenticated low-privilege users, to invoke critical replication-maintenance operations without authorization. This can lead to the removal of replica IDs from replication metadata and disruption of changelog records, potentially resulting in inconsistent or unavailable replication. Organizations using 389 Directory Server, especially those with default settings that permit anonymous access, should prioritize addressing this issue to maintain the integrity and availability of their directory services.
Original NVD Description
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to invoke them otherwise. This allows removal of a replica ID from replication metadata, purging of changelog records, and interruption of administrator-initiated cleanup, which can leave replication inconsistent or unavailable.