← Back

Lemonldap Ng

lemonldap-ng

15 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Lemonldap\
lemonldap\
Apache\
apache\

CVEs (15)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lemonldap Ng
1Lemonldap\
Nov 3, 2025
Oct 9, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default val...Show more
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.Show less
1Lemonldap Ng
1Lemonldap\
Nov 21, 2024
Sep 29, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter...Show more
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.Show less
1Lemonldap Ng
1Lemonldap\
Jan 14, 2025
May 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an at...Show more
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive.Show less
1Lemonldap Ng
1Lemonldap\
Feb 6, 2025
Apr 16, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually r...Show more
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.Show less
1Lemonldap Ng
1Lemonldap\
Feb 14, 2025
Mar 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin th...Show more
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session.Show less
2Debian
Lemonldap Ng
2Apache\
Debian Linux
Apr 3, 2025
Jan 27, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is use...Show more
In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.Show less
2Debian
Lemonldap Ng
2Apache\
Debian Linux
Mar 28, 2025
Jan 27, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE:...Show more
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.Show less
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Nov 21, 2024
Jul 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos...Show more
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.Show less
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Nov 21, 2024
Jul 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl...Show more
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.Show less
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Nov 21, 2024
Jul 30, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be a...Show more
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.Show less
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Nov 21, 2024
Sep 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before...Show more
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.Show less
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
May 28, 2025
Sep 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party...Show more
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.Show less
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
Nov 21, 2024
Jun 28, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
2Debian
Lemonldap Ng
2Debian Linux
Lemonldap\
May 28, 2025
May 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
1Lemonldap Ng
1Lemonldap\
Apr 29, 2026
Jan 1, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.