https://bugs.openldap.org/show_bug.cgi?id=9753
--- Comment #9 from Michael Ströder michael@stroeder.com --- Thinking about this some more: It also seems to have pretty large security impact for all systems/components relying on index attributes for access control decisions, probably also slapd processing ACLs, slapo-unique, slapo-constraint.
IMO it would be worth a public warning via openldap-announce list.