The flaw is in SASL bind handling in 389-ds-base and is classified as CWE-287, Improper Authentication. The ids_sasl_canon_user() function writes the resolved bind DN into a Cyrus SASL auxiliary property on every canonicalization attempt, including failed attempts. A failed one-shot PLAIN exchange does not recreate the SASL context; a later successful SASL bind on the same connection retrieves the property through prop_getnames() and unconditionally trusts the first value, dnval[0].values[0], without checking the mechanism, value freshness, or whether the value matches the identity just authenticated.
The evidence establishes this high-level sequence:
- A failed SASL PLAIN bind can leave
cn=Directory Manager in the auxiliary property.
- A subsequent unrelated successful SASL bind on the same connection can cause the server to retrieve that old DN, including when the second mechanism is SASL ANONYMOUS.
- The server then installs the stale identity instead of the identity actually authenticated and grants Directory Manager authority.
The reported root cause is in ldap/servers/slapd/saslbind.c, specifically ids_sasl_canon_user() and ids_sasl_check_bind(). The returned evidence does not describe the internal patch implementation, such as how the auxiliary property is refreshed or cleared.