Lemonldap-Ng Lemonldap vulnerabilities
13 known vulnerabilities affecting lemonldap-ng/lemonldap.
Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH4MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-48933MEDIUMCVSS 6.1fixed in 2.19.32024-10-09
CVE-2024-48933 [MEDIUM] CWE-79 CVE-2024-48933: A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.
nvd
CVE-2023-44469MEDIUMCVSS 4.3fixed in 2.17.12023-09-29
CVE-2023-44469 [MEDIUM] CVE-2023-44469: A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allo
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.
nvd
CVE-2019-19791CRITICALCVSS 9.8fixed in 2.0.72023-05-29
CVE-2019-19791 [CRITICAL] CVE-2019-19791: In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive.
nvd
CVE-2022-37186MEDIUMCVSS 5.9fixed in 2.0.152023-04-16
CVE-2022-37186 [MEDIUM] CWE-613 CVE-2022-37186: In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted a
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.
nvd
CVE-2023-28862CRITICALCVSS 9.8fixed in 2.16.12023-03-31
CVE-2023-28862 [CRITICAL] CWE-287 CVE-2023-28862: An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session.
nvd
CVE-2021-40874CRITICALCVSS 9.8v\2022-07-18
CVE-2021-40874 [CRITICAL] CWE-287 CVE-2021-40874: An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-i
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized
nvd
CVE-2020-16093HIGHCVSS 7.5≤ 2.0.82022-07-18
CVE-2020-16093 [HIGH] CWE-295 CVE-2020-16093: In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
nvd
CVE-2021-35472HIGHCVSS 8.8≤ 2.0.112021-07-30
CVE-2021-35472 [HIGH] CWE-307 CVE-2021-35472: An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authori
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.
nvd
CVE-2020-24660CRITICALCVSS 9.8≤ 2.0.8≤ 0.5.22020-09-14
CVE-2020-24660 [CRITICAL] CWE-425 CVE-2020-24660: An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass U
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
nvd
CVE-2019-15941CRITICALCVSS 9.8≥ 2.0.0, ≤ 2.0.52019-09-25
CVE-2019-15941 [CRITICAL] CWE-863 CVE-2019-15941: OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access cont
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.
nvd
CVE-2019-13031HIGHCVSS 8.1fixed in 1.9.202019-06-28
CVE-2019-13031 [HIGH] CWE-611 CVE-2019-13031: LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
nvd
CVE-2019-12046CRITICALCVSS 9.8v\2019-05-22
CVE-2019-12046 [CRITICAL] CWE-522 CVE-2019-12046: LemonLDAP::NG -2.0.3 has Incorrect Access Control.
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
nvd
CVE-2012-6426HIGHCVSS 7.5v\≤ 1.2.22013-01-01
CVE-2012-6426 [HIGH] CWE-264 CVE-2012-6426: LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library,
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
nvd