High severity7.5NVD Advisory· Published Jul 18, 2022· Updated Jun 17, 2026
CVE-2020-16093
CVE-2020-16093
Description
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*range: <=2.0.8
- (no CPE)range: <=2.0.8
Patches
Vulnerability mechanics
References
3- gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2250nvdExploitIssue TrackingPatchThird Party Advisory
- lemonldap-ng.org/downloadnvdVendor Advisory
- lists.debian.org/debian-lts-announce/2023/01/msg00027.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.