OpenDJ DSMLv2 Gateway Vulnerability: SSRF, File Read, DoS
An early warning has been issued regarding a vulnerability in the DSMLv2 SOAP gateway of OpenIdentityPlatform OpenDJ, which reportedly allows unauthenticated SSRF, local file read, and unbounded-read DoS. Users of opendj-dsml-servlet version 5.1.1 or earlier are advised to upgrade.
What happened
The DSMLv2 SOAP gateway in OpenIdentityPlatform OpenDJ is under investigation for a vulnerability that appears to enable unauthenticated SSRF, local file read, and unbounded-read DoS attacks. A remote attacker could potentially exploit this to perform server-side request forgery, read local files, and exhaust server memory. The issue has been addressed in version 5.1.2 of opendj-dsml-servlet. It is recommended that users upgrade to this version or later to mitigate potential risks. For more detailed information, consult the primary sources.
How 0Day mitigates this
opendj-dsml-servlet is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.