Bug ID 762385: Wrong remote-role assigned using LDAP authentication after upgrade to 14.1.x and later

Last Modified: Dec 13, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP Install/Upgrade, TMOS(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.4, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 15.0.0, 15.0.1

Fixed In:
15.1.0

Opened: Mar 20, 2019
Severity: 2-Critical

Symptoms

When multiple attributes in a list match multiple roles, the wrong role may be assigned. Alternatively, authentication may fail when check-roles-group is disabled.

Impact

BIG-IP assigns the user to the last attribute in the list that matches a role, potentially yielding a more restrictive set of permissions. Authentication may fail when check-roles-group is disabled.

Conditions

LDAP server replies with a list of attributes (e.g., list of memberOf) where more than one match existing role.

Workaround

None.

Fix Information

The correct remote-role is now assigned using LDAP authentication after upgrade to 15.1.x.

Behavior Change