Medium severity5.9NVD Advisory· Published Apr 16, 2023· Updated Jun 17, 2026
CVE-2022-37186
CVE-2022-37186
Description
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*range: <2.0.15
- (no CPE)range: <2.0.15
- LemonLDAP::NG/LemonLDAP::NGdescription
Patches
Vulnerability mechanics
References
4- gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/59c781b393947663ad3bf26bad0581413dd6fae4nvdPatch
- gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.0.15nvdPatchRelease Notes
- gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2758nvdExploitIssue TrackingPatchVendor Advisory
- lists.debian.org/debian-lts-announce/2023/01/msg00027.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.