CVE-2022-37186
published 2023-04-16CVE-2022-37186: In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur…
PriorityP427medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.73%
50.0th percentile
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lemonldap-ng | < lemonldap-ng 2.0.15+ds-1 (bookworm) | lemonldap-ng 2.0.15+ds-1 (bookworm) |
| lemonldap-ng | lemonldap | < 2.0.15 | 2.0.15 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-37186: lemonldap-ng - In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supp...
vendor_debian·2022·CVSS 5.9
CVE-2022-37186 [MEDIUM] CVE-2022-37186: lemonldap-ng - In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supp...
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.
Scope: local
bookworm: resolved (fixed in 2.0.15+ds-1)
bullseye: resolved (fixed in 2.0.11+ds-4+deb11u2)
forky: resolved (fixed in 2.0.15+ds-1)
sid: resolved (fixed in 2.0.15+ds-1)
trixie: resolved (fixed in 2.0.15+ds-1)
GHSA
GHSA-x33x-q828-vc8w: In LemonLDAP::NG before 2
ghsa_unreviewed·2023-04-16
CVE-2022-37186 [MEDIUM] CWE-613 GHSA-x33x-q828-vc8w: In LemonLDAP::NG before 2
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.
OSV
CVE-2022-37186: In LemonLDAP::NG before 2
osv·2023-04-16·CVSS 5.9
CVE-2022-37186 [MEDIUM] CVE-2022-37186: In LemonLDAP::NG before 2
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/59c781b393947663ad3bf26bad0581413dd6fae4https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2758https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.0.15https://lists.debian.org/debian-lts-announce/2023/01/msg00027.htmlhttps://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/59c781b393947663ad3bf26bad0581413dd6fae4https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2758https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.0.15https://lists.debian.org/debian-lts-announce/2023/01/msg00027.html
2023-04-16
Published