Product:

Lemonldap\:\:

(Lemonldap\-Ng)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 4
Date Id Summary Products Score Patch Annotated
2019-09-25 CVE-2019-15941 OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs. Debian_linux, Lemonldap\:\: N/A
2019-06-28 CVE-2019-13031 LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule. Debian_linux, Lemonldap\:\: 8.1
2019-05-22 CVE-2019-12046 LemonLDAP::NG -2.0.3 has Incorrect Access Control. Debian_linux, Lemonldap\:\: 9.8
2013-01-01 CVE-2012-6426 LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data. Lemonldap\:\: N/A