VYPR

Lemonldap Ng

by Lemonldap Ng

Source repositories

CVEs (24)

  • CVE-2019-19791CriMay 29, 2023
    risk 0.64cvss 9.8epss 0.01

    In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to…

  • CVE-2023-28862CriMar 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does…

  • CVE-2021-40874CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with…

  • CVE-2019-15941CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.02

    OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access…

  • CVE-2019-12046CriMay 22, 2019
    risk 0.64cvss 9.8epss 0.03

    LemonLDAP::NG -2.0.3 has Incorrect Access Control.

  • CVE-2026-92289CriSep 25, 2026
    risk 0.59cvss 9.1epss 0.00

    Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaDataOptionsRequirePKCE set to 2, the…

  • CVE-2026-92288CriSep 25, 2026
    risk 0.59cvss 9.1epss 0.00

    Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. …

  • CVE-2026-19349CriAug 16, 2026
    risk 0.57cvss 9.8epss 0.01

    Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2 state parameter stored as an SSO session in the GitHub and LinkedIn backends. Before redirecting to the identity…

  • CVE-2021-35472HigJul 30, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.

  • CVE-2020-24660CriSep 14, 2020
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.

  • CVE-2019-13031HigJun 28, 2019
    risk 0.53cvss 8.1epss 0.02

    LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.

  • CVE-2021-35473CriNov 10, 2024
    risk 0.52cvss 9.1epss 0.00

    An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected…

  • CVE-2024-45160CriOct 9, 2024
    risk 0.52cvss 9.1epss 0.01

    Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).

  • CVE-2024-52946HigNov 18, 2024
    risk 0.50cvss 8.8epss 0.00

    An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.

  • CVE-2020-16093HigJul 18, 2022
    risk 0.49cvss 7.5epss 0.01

    In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

  • CVE-2025-59518HigSep 17, 2025
    risk 0.45cvss 8.0epss 0.01

    In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

  • CVE-2026-95811MedSep 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost's locationRules regular expressions…

  • CVE-2025-31510HigJan 16, 2026
    risk 0.40cvss 7.2epss 0.00

    In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.

  • CVE-2024-48933MedOct 9, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.

  • CVE-2026-12804MedJun 21, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open…

Page 1 of 2