VYPR
Medium severity5.9NVD Advisory· Published Apr 16, 2023· Updated Jun 17, 2026

CVE-2022-37186

CVE-2022-37186

Description

In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*range: <2.0.15
    • (no CPE)range: <2.0.15
  • LemonLDAP::NG/LemonLDAP::NGdescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.