Skip to main content

Vendor/product archive

lemonldap-ng / lemonldap::ng CVEs

Beta · best-effort

12 CVEs tagged to lemonldap-ng / lemonldap::ng6 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-48933

Published Oct 9, 2024

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if user…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44469

Published Sep 29, 2023

A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs throug…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19791

Published May 29, 2023

In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG se…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-37186

Published Apr 16, 2023

In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28862

Published Mar 31, 2023

An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1