CVE-2020-36658
published 2023-01-27CVE-2020-36658: In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default…
PriorityP339high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.44%
36.0th percentile
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libapache-session-ldap-perl | < libapache-session-ldap-perl 0.5-1 (bookworm) | libapache-session-ldap-perl 0.5-1 (bookworm) |
| lemonldap-ng | apache | < 0.5 | 0.5 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache::Session::LDAP vulnerability
vendor_ubuntu·2024-01-24
CVE-2020-36658 Apache::Session::LDAP vulnerability
Title: Apache::Session::LDAP vulnerability
Summary: Apache::Session::LDAP could be made to expose sensitive information through
spoofing if it received invalid X.509 certificate.
It was discovered that Apache::Session::LDAP incorrectly handled invalid X.509
certificates. If a user or an automated system were tricked into opening a
specially crafted invalid X.509 certificate, a remote attacker could possibly
use this issue to perform spoofing and obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-36658: libapache-session-ldap-perl - In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not ch...
vendor_debian·2020·CVSS 7.5
CVE-2020-36658 [HIGH] CVE-2020-36658: libapache-session-ldap-perl - In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not ch...
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.
Scope: local
bookworm: resolved (fixed in 0.5-1)
bullseye: resolved (fixed in 0.5-1)
forky: resolved (fixed in 0.5-1)
sid: resolved (fixed in 0.5-1)
trixie: resolved (fixed in 0.5-1)
GHSA
GHSA-qf7m-fmfh-9c8v: In Apache::Session::LDAP before 0
ghsa_unreviewed·2023-01-27·CVSS 7.5
CVE-2020-36658 [HIGH] CWE-295 GHSA-qf7m-fmfh-9c8v: In Apache::Session::LDAP before 0
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.
OSV
CVE-2020-36658: In Apache::Session::LDAP before 0
osv·2023-01-27·CVSS 7.5
CVE-2020-36658 [HIGH] CVE-2020-36658: In Apache::Session::LDAP before 0
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/LemonLDAPNG/Apache-Session-LDAP/commit/490722b71eed1ed1ab33d58c78578f23e043561fhttps://lists.debian.org/debian-lts-announce/2023/01/msg00024.htmlhttps://github.com/LemonLDAPNG/Apache-Session-LDAP/commit/490722b71eed1ed1ab33d58c78578f23e043561fhttps://lists.debian.org/debian-lts-announce/2023/01/msg00024.html
2023-01-27
Published