High severity8.1NVD Advisory· Published Jun 28, 2019· Updated Jun 17, 2026
CVE-2019-13031
CVE-2019-13031
Description
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:lemonldap-ng:lemonldap\:\::*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:lemonldap-ng:lemonldap\:\::*:*:*:*:*:*:*:*range: <1.9.20
- (no CPE)range: <1.9.20
- LemonLDAP::NG/LemonLDAP::NGdescription
Patches
Vulnerability mechanics
References
3- gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1820nvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/07/msg00003.htmlnvdThird Party Advisory
- www.calypt.com/blog/index.php/cve-2019-13031-xxe-on-lemonldapng-2-0-5/nvd
News mentions
0No linked articles in our index yet.